1. Introduction and Data Controller
This Privacy Policy explains how SEVA Systems LLC ("SEVA," "we," "us," or "our") collects, uses, discloses, and protects personal information in connection with the website located at https://www.sevasystems.io (the "Site"), the client portal, and SEVA's related Services, as defined in SEVA's Terms of Service.
SEVA Systems LLC, a Wyoming limited liability company, is the data controller responsible for the personal information described in this Policy.
For purposes of Singapore's Personal Data Protection Act, SEVA's Data Protection Officer can be reached at legal@sevasystems.io.
This Policy applies to visitors to the Site, newsletter subscribers, individuals who submit a contact or scope form, and clients using SEVA's client portal. It does not apply to SEVA's Powered By products or owned-code Brands, which are governed by their own separate privacy policies.
If you have questions about this Policy or how SEVA handles your personal information, contact us at legal@sevasystems.io.
2. Categories of Information We Collect
2.1 Information You Provide Directly
We collect information you provide when you:
- Subscribe to our newsletter (email address)
- Submit a contact form (name, email, company name, message)
- Submit a project scope or intake form (name, email, company name, phone number, project details)
- Create a client portal account (name, email, company information, billing contact details)
- Engage SEVA for a project or hosting plan (billing and payment information, processed through Stripe)
2.2 Information Collected Automatically
When you visit the Site, SEVA and its service providers automatically collect certain technical information, including IP address, browser type, device and operating system information, pages visited, and referring source. This information is collected through a self-hosted web analytics platform and content delivery network services, as described in Section 5 (Cookies and Tracking Technologies).
2.3 Categories Under the CCPA
For California residents, the categories of personal information described above correspond to the following CCPA categories: identifiers (name, email, IP address), commercial information (billing and payment details), and internet or network activity information (browsing behavior on the Site).
3. How We Use Your Information
We use the information described in Section 2 for the following purposes:
- To provide the Services — creating and managing your portal account, delivering project work, providing hosting, and processing payments.
- To respond to inquiries — replying to messages submitted through contact or scope forms. Providing your contact information is necessary for us to respond; without it, we cannot process your request.
- To send newsletters and marketing communications — only where you have opted in, as described in SEVA's Marketing Communications policy in its Terms of Service.
- To maintain and improve the Site — analyzing aggregate traffic and usage patterns through the analytics and content delivery services described in Section 5.
- To meet legal and financial obligations — maintaining billing and tax records as required by law.
SEVA does not use information collected for one product or Brand to market a different, distinctly branded product or Brand to the same individual. Each product line maintains its own separately collected audience.
4. Legal Basis for Processing
For individuals in the European Union and United Kingdom, GDPR requires us to identify the specific legal basis for each purpose of processing. The table below maps each purpose described in Section 3 to its legal basis under Article 6 GDPR.
Purpose Legal Basis Providing the Services (portal, project delivery, hosting, payments) Performance of a contract (Article 6(1)(b))
Responding to a project scope or intake inquiry Steps taken at your request prior to entering into a contract (Article 6(1)(b))
Responding to a general contact form inquiry Legitimate interest in responding to business inquiries (Article 6(1)(f))
Sending newsletters and marketing communications Consent (Article 6(1)(a)), withdrawable at any time Site analytics and content delivery Legitimate interest in maintaining and improving the Site (Article 6(1)(f))
Maintaining billing and tax records Legal obligation (Article 6(1)(c))
Where we rely on legitimate interest, we have considered that this processing is unlikely to override your rights and interests, given its limited scope and the privacy-protective measures described in Section 5.
This Section reflects GDPR's legal basis framework specifically. The CCPA does not use a legal basis system; California residents' rights are addressed separately in Section 10 (Your Privacy Rights).
5. Cookies and Tracking Technologies
SEVA uses a limited number of cookies and similar technologies on the Site. These are grouped into the categories below. Full detail on specific cookies, their duration, and how to manage your preferences is available in SEVA's Cookie Policy.
Strictly Necessary. Technologies required for the Site and client portal to function, such as maintaining a login session. These do not require consent.
Analytics. SEVA uses a self-hosted web analytics platform, configured to operate without setting tracking cookies and with visitor data anonymized, consistent with SEVA's standing privacy- protective analytics practice. Because this configuration does not use cookies or track individuals across sites, it does not require cookie consent under applicable law.
Content Delivery and Security. SEVA uses a content delivery network to serve the Site reliably and securely. This service may process technical information, such as IP address, necessary to deliver content and protect against security threats.
Advertising. SEVA does not use advertising cookies, tracking pixels, or similar technologies for behavioral advertising or retargeting.
Consent Management. Where cookie consent is required, SEVA provides a consent management tool allowing you to accept or decline non-essential cookies. Your preferences are recorded and can be changed at any time.
6. Third-Party Service Providers
SEVA shares personal information with service providers who perform functions on our behalf, under contractual terms that limit their use of that information to providing services to SEVA.
These include providers of:
- Payment processing (billing and payment information)
- Accounting and bookkeeping (billing contact and payment records)
- Email delivery and marketing (email address, only for individuals who have opted in)
- E-signature and contract execution (name, email, signature data)
- Cloud storage and hosting infrastructure (project files, account data)
- Website analytics and content delivery, as described in Section 5 SEVA's internal team, including employees and contracted development partners who require access to deliver the Services, may also access personal information solely for that purpose.
Where a service provider or development partner is located outside your country, this may involve an international transfer of your information, as described in Section 8.
7. Do We Sell or Share Your Information (CCPA)
SEVA does not sell personal information, as that term is defined under the CCPA.
SEVA does not share personal information for cross-context behavioral advertising, as that term is defined under the CCPA. SEVA does not use advertising pixels or similar technologies, as described in Section 5.
Because SEVA does not sell or share personal information, there is no opt-out mechanism to describe under this Section. If SEVA's practices change in the future, this Policy will be updated, and an opt-out mechanism will be provided consistent with CCPA requirements at that time.
8. International Data Transfers
SEVA is based in the United States. If you are located in the European Economic Area (EEA) or United Kingdom, your personal information will be transferred to, stored, and processed in the United States, and may also be accessed by SEVA's development partners located outside the EEA or UK.
Where such a transfer occurs, SEVA relies on Standard Contractual Clauses approved by the European Commission as the safeguard for that transfer, together with any additional technical and organizational measures necessary to protect your information.
Certain hosting infrastructure used to deliver the Services may be located within the EEA. Where this is the case, it does not eliminate the need for a transfer safeguard, because SEVA's access to and control over that data from the United States is itself considered a transfer under applicable law.
You may request further information about the safeguards used for a specific transfer by contacting legal@sevasystems.io.
9. Data Retention
SEVA retains personal information only as long as necessary for the purposes described in this Policy, or as required by law. Retention periods vary by category, as set out below.
10. Your Privacy Rights
10.1 Rights for Individuals in the EEA and UK (GDPR)
If you are located in the European Economic Area or United Kingdom, you have the right to:
- Access the personal information SEVA holds about you
- Correct inaccurate personal information
- Request erasure of your personal information
- Restrict or object to certain processing
- Receive your personal information in a portable format
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with your local supervisory authority, regardless of whether you have first contacted SEVA Category Retention Period Client portal and project account data For the duration of your engagement with SEVA, plus 30 days following termination, during which you may export your data, consistent with Section 11.6 of SEVA's Terms of Service Billing, invoice, and payment records Up to seven (7) years, as required for tax and legal compliance, consistent with Section 11.6 of SEVA's Terms of Service Newsletter subscriptionUntil you unsubscribe or withdraw consent Contact and scope form submissions Up to 12 months following your inquiry, unless the inquiry results in an active engagement, in which case the retention periods above apply Site analytics data Retained in aggregated or anonymized form; not linked to an identifiable individual
10.2 Rights for California Residents (CCPA)
If you are a California resident, you have the right to:
- Know what personal information SEVA collects, uses, and discloses about you
- Delete personal information SEVA has collected from you
- Correct inaccurate personal information
- Non-discrimination for exercising any of these rights As described in Section 7, SEVA does not sell or share personal information, so there is no right to opt out of sale or sharing to exercise at this time.
10.3 How to Exercise Your Rights
To exercise any of these rights, contact legal@sevasystems.io. SEVA will verify your identity before fulfilling a request, and will respond within the timeframe required by applicable law.
11. Automated Decision-Making
SEVA does not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you. All decisions regarding your inquiries, projects, and engagement with SEVA are made by SEVA's team.
12. Children's Privacy
SEVA's Services are not directed to individuals under 18, and SEVA does not knowingly collect personal information from anyone under 18, consistent with the age requirement in Section 1 of SEVA's Terms of Service.
If SEVA becomes aware that it has collected personal information from someone under 18, SEVA will delete that information promptly. If you believe SEVA has collected information from a minor, contact legal@sevasystems.io.
13. Security
SEVA implements technical and organizational measures designed to protect personal information against unauthorized access, disclosure, alteration, or destruction, consistent with SEVA's data sovereignty and confidentiality commitments.
These measures include encrypted connections, role-based access controls, and secure infrastructure practices. No method of transmission or storage is completely secure, and SEVA cannot guarantee absolute security.
If SEVA experiences a security incident affecting your personal information, SEVA will notify affected individuals and relevant authorities as required by applicable law.
14. Changes to This Policy
SEVA may update this Privacy Policy from time to time. Material changes will be communicated by posting a notice on the Site and, where you have a portal account, by email to the address on file. Your continued use of the Services after a change takes effect constitutes acceptance of the revised Policy.
The "Last Updated" date at the top of this Policy reflects the most recent revision.
15. Contact Us
If you have questions about this Privacy Policy, or wish to exercise any of the rights described in Section 10, contact us:
By email: legal@sevasystems.io