Effective date: 17 August 2026 · Version 2.4
This Notice describes how Seedfor collects, uses, shares, and protects personal information, and the rights of individuals in the European Economic Area, the United Kingdom, Switzerland, the United States (including California, Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws), and other jurisdictions. It applies to the website at seedfor.io during its pre-launch phase. The companion Terms of Use governs your use of the Website itself; this Notice governs the processing of personal data.
What changed in v2.2 (19 May 2026): §12 cookies / local-storage table updated to list new per-chart persistence keys introduced by the Dataroom version selector (sf_*_version, sf_what_framework), per-chart legend / active-set / pinned-cluster memory keys, and the demonstration-data drafts authored on the Settings, Marketplace, DAO, Lending and AI-Marketplace pages. §01 now cross-references the companion Terms of Use. No change to data categories collected, processors, retention, or your rights.
Scope, applicability, and key definitions
This Privacy Notice ("Notice") explains how we, the operators of the Seedfor project ("Seedfor", "we", "us", "our"), process personal data and personal information (collectively, "personal data") when you visit seedfor.io ("Website"), interact with the embedded waitlist form, contact us by email, or access the authenticated management portal.
This Notice does not apply to: (a) third-party websites linked from the Website; (b) future smart-contract or on-chain interactions, which will be governed by a separate, additional notice published prior to launch.
For the purposes of this Notice and applicable law:
Data controller / business operator
The data controller (under the GDPR and UK GDPR) and the "business" (under the CCPA/CPRA and analogous US state laws) is an Italy-based natural person operating the Seedfor project on a pre-launch and pre-incorporation basis. A legal entity will be established prior to the public launch of the platform, at which point full identification details (registered name and address) will be published in this Notice.
Until that date, all data-protection enquiries should be directed to the contact below.
The European supervisory authority of competent jurisdiction is the Italian Garante per la Protezione dei Dati Personali (https://www.gpdp.it). The lead supervisory authority for cross-border processing may change once a legal entity is incorporated.
Seedfor is below the thresholds at which appointment of a Data Protection Officer is mandatory under GDPR Art. 37 or the thresholds at which a Privacy Officer is required under specific US state laws; nevertheless, a dedicated contact point is maintained at the email address above.
Categories, sources, and CCPA mapping
a) Waitlist subscription (via Beehiiv)
The waitlist form embedded on the Website is provided by Beehiiv Inc. and posts directly to Beehiiv's servers. All waitlist submissions on the Website (including those triggered from the "in-progress" cards on individual feature pages) open the same Beehiiv-hosted embedded form, so the email address you submit is sent directly to Beehiiv and is not retained on Seedfor-controlled infrastructure (other than ephemeral server logs limited to the events listed in §03(c)).
b) Direct email communications
c) Authenticated portal access (authorised users only)
When an authorised user (a small allow-list of management email addresses, kept private) requests a one-time access code or verifies one, we process:
Sign-in flow in plain language. An authorised user types their allow-listed email into the access form and receives a 6-digit code by email. The code is valid for 15 minutes from issue, single-use, and tied to the specific browser that requested it (it cannot be forwarded to a different device or browser). After successful verification, an authenticated session lasts 24 hours in the same browser; during that window no further codes are needed. Sessions end automatically when the 24-hour timer elapses or when the user explicitly signs out (which deletes the session cookies immediately). The composition of the allow-list is not published.
d) Use Case research lookups
When you type a business name into the "Use Case" tab on the homepage (the optional text field next to the User-type slider), your browser sends the name to our /api/biz-research endpoint, which forwards it to Anthropic PBC (the Claude API, with the web-search tool enabled) for the sole purpose of returning three strategic use-case bullets. The request payload is the business name and your IP & User-Agent; no name is persisted in our database, and our backend logs include only the rate-limit IP counter, not the name itself. Identical lookups within 24 hours are served from Vercel's edge cache so the same name is not re-sent to Anthropic for the cache window. You can refrain from typing in this field at any time — the rest of the tab works without it.
e) Browser error reporting
If a JavaScript error occurs in your browser on a Seedfor page, the message, page URL, line/column number, and stack trace are submitted to our /api/log-error endpoint. Each payload is capped at 2 KB; per-IP submissions are rate-limited; entries are retained only in Vercel's standard log retention window (see §08).
f) Information we do NOT collect
f) CCPA / CPRA category mapping
For California residents, the personal information described above maps to the CCPA/CPRA statutory categories as follows:
| CCPA Category | Collected? | Source |
|---|---|---|
| Identifiers (email, IP) | Yes | You (form), automatically (web server) |
| Personal records (Cal. Civ. Code §1798.80(e)) | No | — |
| Protected classifications | No | — |
| Commercial information | No | — |
| Biometric information | No | — |
| Internet activity (browser-error events) | Yes, minimally | Automatically, on JS error |
| Geolocation | Coarse (city/country from IP only) | Automatically by infrastructure providers |
| Sensory data | No | — |
| Professional/employment | Only if you provide it via email | You |
| Education | No | — |
| Inferences | No | — |
| Sensitive personal information (CPRA) | No | — |
Purposes of processing
We use personal data for the following purposes only:
We do not:
Article 6 grounds
Who we share data with
We do not sell personal data and do not share it with third parties for advertising or marketing. We disclose personal data only to the service providers ("processors") listed below, each engaged under a written agreement that complies with GDPR Art. 28 and includes EU Standard Contractual Clauses where applicable:
| Processor | Role | Location | Reference |
|---|---|---|---|
| Vercel Inc. | Web hosting, serverless functions, edge middleware, infrastructure logs | USA (with EU PoPs) | vercel.com/legal/dpa |
| Beehiiv Inc. | Email-marketing platform; waitlist management; transactional welcome / launch emails | USA | beehiiv.com/dpa · subprocessors at subprocessors.beehiiv.com |
| Resend Inc. | Transactional email delivery (one-time access codes only) | USA | resend.com/legal/dpa |
| Upstash, Inc. (if enabled) | Serverless Redis for rate-limit and brute-force counters keyed on IP (no email content) | USA / EU regions available | upstash.com/trust/dpa.pdf |
| Intuition Machines, Inc. (hCaptcha) (if enabled) | Bot-mitigation CAPTCHA challenge on the access form | USA | hcaptcha.com/privacy · hcaptcha.com/terms |
| Google LLC (Google Fonts, Google Workspace) | Web-font delivery (fonts.googleapis.com / fonts.gstatic.com); business-email hosting for management@seedfor.io |
USA / EU | workspace.google.com/terms/dpa_terms.html |
| Anthropic, PBC (Claude API + web-search tool) | Returns three strategic use-case bullets when you type a business name into the "Use Case" tab (see §03(d)). Receives the business name plus our server-issued API key — never your email, IP, or any other identifier. | USA | anthropic.com/legal/dpa · anthropic.com/legal/privacy |
We may also disclose personal data:
User-triggered third-party endpoints (no Art. 28 controller / processor relationship)
Certain features on the Website cause your browser to query public third-party APIs directly. These calls are not routed through our servers and we receive no copy of the request or response — but each provider receives your IP address, User-Agent, and the query string you generated. We list them here for transparency. Disclosing your data to them is necessary to deliver the feature you triggered; the lawful basis under GDPR Art. 6(1)(f) is our and your legitimate interest in providing that feature.
| Service | Triggered by | What is sent | Reference |
|---|---|---|---|
| Wikimedia Foundation, Inc. (Wikipedia API) | Typing in or selecting a business in the BMC composer on the On-Chain MSME page | The business name you typed or selected (sent in the URL query string); your IP & User-Agent | foundation.wikimedia.org/wiki/Policy:Privacy_policy |
| OpenStreetMap Foundation (Nominatim geocoding + tile servers) | Opening the map pointer on the On-Chain MSME or About page | Map viewport coordinates and any free-text search you submit; your IP & User-Agent | wiki.osmfoundation.org/wiki/Privacy_Policy |
| GitHub, Inc. (api.github.com — public commits endpoint) | Loading any page on the site (footer reads the last-commit timestamp for transparency) | An unauthenticated GET request to the public SeedForMgmt/SeedforW repository; your IP & User-Agent |
docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement |
| jsDelivr (Prospect One) · unpkg | Loading any chart page (Chart.js, chartjs-plugin-annotation, Leaflet are served from these CDNs) | The asset URL you requested; your IP & User-Agent. No cookies are set. | jsdelivr.com/privacy-policy · unpkg.com |
These providers act as independent controllers of any data they collect from your browser. We have no contractual access to that data. You can block the calls at the browser level (privacy extensions, content-blockers, or a custom Content-Security-Policy override in your browser) without affecting the rest of the Website — the affected features will simply degrade gracefully (the BMC composer will fall back to its keyword-only classification path; the map pointer will not load; the footer will display "Last commit: unavailable").
Transfers outside the EEA / UK / Switzerland
Several of our processors are located in the United States. When personal data is transferred from the EEA, the UK, or Switzerland to the United States or other third countries, we rely on the following legal transfer mechanisms under GDPR Chapter V:
We have conducted a transfer-impact assessment that considered the legal regime of the destination country, the categories of data transferred, the technical and organisational safeguards in place, and the likelihood of public-authority access requests. Where a transfer-impact assessment identifies risk that cannot be mitigated by contractual measures alone, we apply supplementary measures (such as end-to-end transport encryption, hashed identifiers, minimised payloads, and short retention windows).
You may request a copy of the safeguards applicable to a specific transfer by contacting us at the address in §18.
How long we keep your data
| Data category | Retention period |
|---|---|
| Waitlist email and consent record (at Beehiiv) | Until you unsubscribe, until you request deletion, or up to 24 months after the official public launch of the Seedfor platform — whichever is earliest. |
| Email correspondence with us | Up to 24 months from the date of the last meaningful exchange, unless a longer period is required to defend a legal claim. |
| Server-side audit and access logs (IP, hashed email, event, timestamp) | Maximum 30 days within Vercel's infrastructure logging system, after which they are automatically purged. Not exported, archived, or used for any purpose other than security monitoring. |
| Browser-error logs | Same as above — maximum 30 days. |
| Rate-limit and brute-force counters (Upstash Redis or memory) | Auto-expire 15 minutes after the last increment. |
One-time-code session (sf_otp) | 15 minutes (cookie auto-expires; single-use) |
Authenticated session (sf_auth, sf_status) | 24 hours from issue (or until logout) |
Rights under the GDPR, UK GDPR, and Swiss FADP
Subject to applicable conditions and exceptions, you have the right to:
To exercise any of these rights, email management@seedfor.io. We will respond within one month (extendable by two further months in complex cases, per Art. 12(3)). We may need to verify your identity before fulfilling certain requests.
For California residents only
California consumers have the rights described below under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"). The categories of personal information we collect and the sources are set out in §03(f); the business purposes for which we use them are listed in §04; the categories of recipients are in §06.
Your CCPA/CPRA rights
How to exercise your CCPA rights
Email management@seedfor.io with the subject "California Privacy Request". We will verify your identity using information we already hold (typically the email address used to interact with us). We will respond within 45 days (extendable by 45 days on notice). You may use an authorised agent to submit a request; we will require written proof of authorisation.
"Do Not Sell or Share My Personal Information"
We do not sell or share personal information. No "Do Not Sell or Share" mechanism is therefore required; however, if you wish to confirm this preference for the record, email us at the address above.
Global Privacy Control (GPC)
Because we do not engage in sale or sharing of personal information, GPC signals received from your browser produce no operational change. We honour user preferences as a matter of policy.
"Shine the Light" disclosure
Under California Civil Code §1798.83 ("Shine the Light"), California residents may request a list of the personal information disclosed to third parties for those third parties' direct-marketing purposes during the prior calendar year. We do not disclose personal information to third parties for their direct-marketing purposes.
Notice of financial-incentive programmes
We do not offer financial incentives or price/service differences based on the collection or sharing of personal information.
VCDPA (VA), CPA (CO), CTDPA (CT), UCPA (UT), and similar state laws
If you are a resident of Virginia, Colorado, Connecticut, Utah, or another US state that has enacted a comprehensive consumer-privacy law (including, where applicable, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, Minnesota, Tennessee, Indiana, and Kentucky), you may have the following rights, subject to that state's specific definitions, thresholds, and exceptions:
To exercise these rights, email management@seedfor.io with the subject "US State Privacy Request" and identify your state of residence. We will respond within the timeframe required by that state's law (typically 45 days). If we deny a request, you may appeal by replying within a reasonable time, and we will reconsider and respond within the period required by your state's law. Where your state offers a right to complain to the state Attorney General, instructions will be provided in our response.
Strictly necessary technologies; no advertising trackers
The Website does not use advertising, analytics, or cross-context behavioural-tracking cookies, and does not load Google Analytics, Meta Pixel, TikTok Pixel, or similar trackers. We therefore do not display a cookie-consent banner: under Article 5(3) of the ePrivacy Directive, cookies and similar technologies that are strictly necessary to provide a service requested by the user are exempt from prior-consent requirements.
a) First-party HTTP cookies
| Name | Purpose | Duration | HttpOnly? |
|---|---|---|---|
sf_otp | Signed token holding the one-time access code, used to verify the code you type. Single-use and cleared the moment a valid code is verified. | 15 minutes | Yes |
sf_auth | Signed JWT confirming a valid authenticated session; verified by edge middleware on every gated page | 24 hours | Yes |
sf_status | UI signal (value 1) so the client knows a valid session exists; carries no personal data | 24 hours | No (intentionally readable to JS for UI) |
All three cookies are Secure and SameSite=Strict. They are strictly necessary to provide the authenticated management portal.
b) Browser localStorage (strictly necessary, on-device)
Local-storage values remain on your device, are not transmitted to any server, and are cleared when you clear site data in your browser.
| Key | Purpose |
|---|---|
sf_logout | Timestamp written on logout; signals other tabs of the same browser to terminate the session. |
sf_wip_unlock | Flag indicating the in-progress / coming-soon overlay has been dismissed. |
sf_demo | Flag indicating demo mode is active (staging environments only). |
sf_guest_session | Flag indicating an unauthenticated "guest" view on the DAO page; contains no personal data. |
sf_biz, sf_geo, sf_sector, sf_size | Filter and search preferences (business name typed into the search, geography/sector/size filter selections). |
sf_biz_facet, sf_facet_user, sf_facet_credit, sf_facet_chain | "Use Case" tab state on the homepage hero — the business name typed into the optional field plus the three slider positions (user-type, credit-type, blockchain-integration). Used to restore your tab state across reloads. Session-scoped sibling keys with the prefix sf_biz_research: cache the bullet output from /api/biz-research for 1 hour so retyping the same name is instant and does not re-hit the endpoint. |
sf_biz_live, sf_biz_name, sf_biz_bmc_html, sf_biz_bmc_legend, sf_biz_sdg_html, sf_biz_sdg_legend, sf_biz_kpi, sf_biz_tokens_html, sf_biz_groups | Drafts of the business-model canvas, SDG canvas, KPIs, tokens, and grouping you have authored on the business page; kept locally so your work is not lost on reload. |
sfd_biz_cluster | Selected business-cluster configuration (geography/sector/size) on settings and business pages. |
sfd_kyc_status, sfd_kyb_status | Local indicator of where you are in the (placeholder) KYC/KYB workflow. No identity documents are processed at this stage; values only reflect "unverified" or "pending". |
sfd_investor_class | Local indicator of your professional / qualified-investor status. Used to gate access to Seedfor's own tokens (SfC / SdT / SfT), which are offered solely to qualified investors. Placeholder pre-launch — no documents are processed at this stage; values only reflect "unverified", "pending" or "qualified". |
sfd_ai_key | An AI API key you may optionally paste into the settings page to enable optional AI-assisted features locally. This key is stored only on your device and never transmitted to our servers. You may delete it at any time by clearing site data or by emptying the field in settings. |
sfd_bg_projects, bmcFormSaved | Drafts of saved business-page projects and form state. |
sfToken, sfMQRCodes | Token-related identifiers and QR codes generated locally for demo/preview purposes. |
sf_sft_addr | Last-connected MetaMask wallet address (shortened & full). Stored only after the user explicitly clicks Launch App → Connect Wallet → MetaMask; used to optimistically paint the in-nav SfT badge on cross-page navigation. Cleared on disconnect. |
sf_pg_rd_what, sf_pg_rd_why, sf_pg_sells, sf_pg_buys, sf_pg_mkt_lend, sf_pg_mkt_borr, sf_pg_mkt_back, sf_pg_mkt_acrb, sf_pg_val, sf_pg_fcst | Per-table pagination state ({expanded, page}) so the 5/20-per-page view you chose on each entity table persists across reloads and navigation. |
sf_bizrow_visible_land1 | Whether the under-header business-search row on the homepage is expanded. Toggled by double-clicking the logo. |
sf_demo_exit | Per-tab flag that records the user has explicitly exited demo mode. |
sf_msel_geo, sf_msel_sec, sf_msel_size, sf_msel_wGeo, sf_msel_wSec, sf_msel_wSz, sf_msel_whyGeo, sf_msel_whySector, sf_msel_whySize, sf_msel_globalGeo, sf_msel_globalSector, sf_msel_globalSz | Per-chart multi-select filter selections so the chosen Geography / Sector / Size clusters persist across reloads. |
sf_why_version, sf_what_version, sf_where_version, sf_who_version | The model-data version (e.g. v3.99.7, SeedforV2a) the user picked in the Dataroom for each chart page. The chart pages read these so they render the calibrated dataset the user selected. |
sf_what_framework | The active modelling framework on the Risk Transfer chart (e.g. BaselP1, SeedforV1, SeedforV2a, SeedforV2b, SeedforV3). Drives the formula used to compute the Excess Credit Premium and tail-risk numbers shown. |
sf_why_series_state, sf_what_series_state, sf_where_series_state | Per-chart legend memory recording which series (and which states — line only, line+band, or hidden) you toggled, so the chart restores your view on reload. |
sf_why_active_set, sf_what_active_set, sf_where_active_set, sf_who_active_set | Per-chart memory of the active multi-cluster set you assembled, so the chart restores the same combination across reloads. |
sf_why_pinned, sf_ww_pinned | The single cluster you "pinned" on the Credit Access or Risk Transfer chart so a focused detail card persists across reloads. |
sf_user_email, sf_logged_in, sf_wallet, sf_bizrow_visible | UI-only signals for the access portal — they record (locally) the email you typed into the access form, whether a valid authenticated session exists, an optional placeholder wallet identifier you supplied, and whether the "business search" row is unhidden. No identity verification occurs at this stage. |
sfd_bmc_corpus, sfd_cashflow, sfd_defi_flows, sfd_esg_scores, sfd_fundraise, sfd_nft_traits, sfd_sbt_meta, sfd_sdg_mapping, sfd_sector_bench, sfd_strategy, sfd_txn_sme, sfd_wallet_profiles, sfd_settings_panel, sfd_sycr_alerts2, sfd_wall_load_project | Draft / placeholder content for the pre-launch demonstration pages (Settings, Marketplace, DAO, Lending Market, AI Marketplace, On-Chain MSME). These keys hold mock data you author or load while exploring the demo — they never leave your browser. |
sf_dr_uid_v1, sf_dr_uid_v1_name | A pseudonymous identifier (e.g. r3a7b2) and a derived "Researcher #" handle assigned to your browser so your Flag-a-bug votes and comments are not double-counted. Not linked to any account. |
sf_dr_flags_v1 | Local Flag-a-bug "Discussion" thread for the four chart datasets — your draft + posted flag content, comments, and like/dislike votes. Stored only on your device; no server roundtrip. See §19 below for how this changes when an intake pipeline goes live. |
sf_gh_commit_v1 | Cached GitHub last-commit timestamp shown in the footer (10-minute TTL). Holds only a date string; no identifiers. |
sf_wip_unlock, sf_status | UI signals for one-time "Continue past warning" actions and authenticated-session presence. |
sf_srt_feedback | Free-text feedback you optionally type into the homepage "SRT journey" explainer (the Risk-transfer decision-tree pop-up), with the choice you selected and a timestamp. Stored only on your device; no server roundtrip. Same treatment as Flag-a-bug (§19) — there is no backend, so it is never sent to Seedfor. |
If a future feature requires non-essential storage or tracking, we will implement a granular consent mechanism (GDPR Art. 7 / ePrivacy Art. 5(3)) before any such storage is performed, and update this Notice.
How to clear stored preferences. You can delete every key listed above at any time by clearing site data in your browser (in Chrome / Edge: Settings → Privacy and security → Site settings → View permissions and data stored across sites → seedfor.io → Clear data; equivalent paths exist in Firefox and Safari). The Dataroom (tools/chart-csv.html) also exposes a Reset stored preferences button that wipes only the sf_* keys belonging to this Website and reloads the page.
c) Third-party scripts and iframes
subscribe-forms.beehiiv.com) — loaded only when you actively click "join waitlist" / the bell icon. When loaded, Beehiiv may set first-party cookies on its own domain that are strictly necessary for spam prevention and form security. By submitting your email through this form you consent to Beehiiv processing it as described in Beehiiv's privacy policy and DPA.js.hcaptcha.com, *.hcaptcha.com) — loaded on the access page only when bot mitigation is enabled. hCaptcha may set strictly-necessary cookies for challenge integrity. hCaptcha does not use the data for behavioural advertising; see hcaptcha.com/privacy.fonts.googleapis.com, fonts.gstatic.com) — used to render the Inter typeface. Requests reveal IP and user-agent to Google solely for the duration of the font request; no cookies are set by Google Fonts.d) Content Security Policy
The Website serves a strict Content-Security-Policy that restricts script, style, image, font, and frame sources to those listed above, prevents framing of the site, and forbids embedded objects.
Technical and organisational measures (GDPR Art. 32)
We implement, and require our processors to implement, technical and organisational measures appropriate to the risk, including:
includeSubDomains and preload)X-Frame-Options: DENY, X-Content-Type-Options: nosniff, restrictive Permissions-Policy, and Referrer-Policy: strict-origin-when-cross-originHttpOnly, Secure, SameSite=Strict cookies; constant-time signature comparison; cryptographically secure random number generationIn the event of a personal-data breach affecting EU/UK residents likely to result in a risk to their rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware (GDPR Art. 33). Where the breach is likely to result in a high risk, affected users will be notified without undue delay (Art. 34). US state-law breach-notification timelines will be followed where applicable.
Minors and age restrictions
The Website is not directed at, and we do not knowingly collect personal data from, individuals under 18 years of age. In the United States, the Website is also not directed at children under 13 within the meaning of the Children's Online Privacy Protection Act (COPPA, 15 U.S.C. §§6501–6506). If you believe we have inadvertently processed personal data of a minor, contact management@seedfor.io and we will delete it promptly.
We do not engage in automated decision-making — including profiling — that produces legal or similarly significant effects on you within the meaning of GDPR Art. 22 or analogous US state-law provisions. CAPTCHA bot-detection, where enabled, applies a heuristic only to the immediate access request; no profile is built or stored.
AI-assisted classification and generation
Several pre-launch features apply automated classification or text generation. None of these features makes a decision with legal or similarly significant effect on you, and you can override or ignore the output at any time:
scripts/audit_charts.py) runs a fixed set of structural checks on the chart-data files on every commit and pull request. The checks operate on Seedfor's own data files; no user input is processed.None of these features produces legal effects, financial obligations, or credit-eligibility determinations. They support exploration and discussion — they are not regulated assessments and should not be relied on as such. See §20 (Risk Disclosures) below.
Wallet addresses, on-chain data, and tokenisation
Seedfor is developing a Web3 platform that, at launch, may involve interactions with public blockchains, wallet addresses, and tokenised credit instruments. Under European Data Protection Board guidance, wallet addresses are considered personal data when combined with other information. Smart-contract interactions are recorded on public, immutable ledgers.
A dedicated and additional privacy notice will be published before any such processing begins. It will describe: (a) how blockchain data is processed; (b) the legal basis; (c) limitations arising from blockchain immutability and the practical limits of the GDPR rights to erasure and rectification in that context; and (d) how risks are mitigated (off-chain storage of personal data, pseudonymisation, hashed identifiers).
No blockchain-related personal data processing occurs at the current pre-launch stage.
We may update this Notice to reflect changes in our practices, our processors, or applicable law. The "Effective date" at the top of this Notice indicates the most recent revision. Material changes will be communicated to waitlist subscribers by email and, where required by applicable law, with prior notice and a renewed consent mechanism. Continued use of the Website after the effective date constitutes acceptance of the revised Notice to the extent permitted by law.
For any privacy enquiry, to exercise your rights, or to raise a concern:
If you are not satisfied with our response, you may lodge a complaint with the supervisory authority or attorney general of your jurisdiction (see §09, §10, §11).
Dataroom uploads, Flag-a-bug discussions, and similar contributions
The Website contains a few channels through which you may submit material to Seedfor. At the current pre-launch stage, none of them is wired to a backend — your submissions stay in your browser's localStorage (Flag-a-bug discussions, and the homepage "SRT journey" feedback) or in the file picker dialog (Dataroom upload) until you explicitly forward them to us by email. This section describes both the current behaviour and the forward-looking framework that will apply once the intake pipelines go live.
a) Dataroom dataset uploads
Each chart card in tools/chart-csv.html exposes an Upload dataset (JSON / CSV) button. Today the button stages the file in the browser, shows a confirmation listing the filename and size, and asks you to email the file to management@seedfor.io with a chart-specific subject. The file is not transmitted anywhere by the Website itself.
By emailing a file to us — or, in the future, by submitting it through an in-app intake pipeline — you confirm that (i) you have the right to share the data (it is yours, public, or licensed for redistribution); (ii) the file does not contain personal data of identifiable third parties; (iii) the file does not contain copyrighted extracts from paywalled commercial sources (S&P, Bloomberg, Cerved, Messari, MSCI subscription products, etc.) that you are not authorised to redistribute; (iv) the file does not contain material non-public information about identifiable companies; and (v) you grant Seedfor a non-exclusive, royalty-free, worldwide licence to use the data for calibration of the chart-data files described in §15 of this Notice. We do not republish raw uploads — only derived multiplier values aligned to the published methodology — and we identify the source publicly only in the chart's references file (so attribution is preserved). You may request deletion of an upload at any time by emailing the same address.
b) Flag-a-bug discussions
Each chart card in the Dataroom carries a Flag a bug button that opens a per-section discussion thread. Today every flag, comment, like and dislike is written only to localStorage on your device (key sf_dr_flags_v1, see §12). No data is sent to Seedfor's servers. The discussion thread is therefore visible only to your own browser. The "Researcher #" handle and the underlying pseudonymous identifier in sf_dr_uid_v1 are generated locally and not linked to any account.
Before any Flag-a-bug intake goes live with a backend — which would mean your submissions are sent to Seedfor and could be displayed to other users — we will publish (and link from the Dataroom) a short Contributor Notice covering: the licence grant you provide to Seedfor for the submitted content; our right to remove content that violates law, third-party rights, or community standards; the takedown / notice-and-action procedure (including a contact channel for IP-rights claims and a request-for-removal channel for content concerning you personally); and the moderation criteria we apply.
c) Right of removal
For any content you have already shared with us by email under (a) above, you may request its removal at any time at management@seedfor.io. We will action the request within a reasonable period and, where the content has been incorporated into the calibration data, we will note the removal in the chart's audit log without disclosing your identity.
What the published values are, and what they are not
The four charts on the Website (Credit Access, Risk Transfer, Risk Forecast, On-Chain MSME) and the underlying datasets in /data/ are published for transparency, educational and discussion purposes. To avoid any misunderstanding about the legal status of these outputs:
By using the Website you acknowledge the limitations described in this section.