Data Policy

Last updated: 1 April 2026

1. Data Classification

All data on the Septimius platform is classified into four tiers:

  • Tier 1 — Public: Non-sensitive data (e.g., product descriptions, public pages).
  • Tier 2 — Internal: Operational data (e.g., fund names, property records).
  • Tier 3 — Confidential: Sensitive business data (e.g., financial calculations, NAV records).
  • Tier 4 — Restricted: Highly sensitive data (e.g., PII, authentication credentials).

2. Data Storage

All data is stored in Supabase PostgreSQL databases in eu-west-1 (Ireland). Encrypted at rest (AES-256) and in transit (TLS 1.3). Row-level security enforces access control at the database level.

3. Data Retention

Active account data is retained for the duration of the account. Financial records are retained for a minimum of 7 years per regulatory requirements. Backups retained for 30 days.

4. Data Processing

Data is processed within the EU (eu-west-1). We do not sell data to third parties.

5. Contact

Data inquiries: data@septimius.io

Part of the Septimius Ecosystem