Data Policy
Last updated: 1 April 2026
1. Data Classification
All data on the Septimius platform is classified into four tiers:
- Tier 1 — Public: Non-sensitive data (e.g., product descriptions, public pages).
- Tier 2 — Internal: Operational data (e.g., fund names, property records).
- Tier 3 — Confidential: Sensitive business data (e.g., financial calculations, NAV records).
- Tier 4 — Restricted: Highly sensitive data (e.g., PII, authentication credentials).
2. Data Storage
All data is stored in Supabase PostgreSQL databases in eu-west-1 (Ireland). Encrypted at rest (AES-256) and in transit (TLS 1.3). Row-level security enforces access control at the database level.
3. Data Retention
Active account data is retained for the duration of the account. Financial records are retained for a minimum of 7 years per regulatory requirements. Backups retained for 30 days.
4. Data Processing
Data is processed within the EU (eu-west-1). We do not sell data to third parties.
5. Contact
Data inquiries: data@septimius.io