SENECArisk intelligence ← Back to seneca-risk.com

Privacy Policy

Last updated: 17 June 2026

This Privacy Policy explains how Vladyslav Nedodaiev (“Seneca”, “we”, “us”), operating Seneca Risk Intelligence at seneca-risk.com and app.seneca-risk.com, collects and uses your personal data, and the rights you have under the EU/UK General Data Protection Regulation (GDPR).

1. Who we are (Data Controller)

Vladyslav Nedodaiev, DMCC Business Centre, Level No 1, Jewellery & Gemplex 3, Dubai, United Arab Emirates. Contact for privacy matters: privacy@seneca-risk.com.

2. The personal data we collect

  • Account data — your email address, display name and sign-in method (email/password, Google, or Apple), and whether your email is verified. Provided when you create an account.
  • Subscription & billing data — your subscription status, plan, trial dates, and a Stripe customer ID. We never receive or store your card number — payments are handled on Stripe's hosted checkout.
  • Usage & analytics data — only with your consent: device and browser type, approximate location derived from a truncated IP, pages viewed and in-product events, collected via Google Analytics 4.
  • Technical/essential data — small cookies required to run the service (your signed-in/tier hint and your cookie-consent choice) and your authentication session (held by Firebase Auth in your browser).
  • Forecast personalization — a per-user pseudonymous value used to tailor the data served to your account; it is tied to your account but is not used to identify you outside the service.

We do not intentionally collect special-category data (health, biometrics, etc.), and the service is not directed to children (see §9).

3. Why we use it, and our legal basis (GDPR Art. 6)

PurposeDataLegal basis
Create/operate your account and deliver the forecastsAccount, technicalPerformance of a contract (Art. 6(1)(b))
Process subscriptions, trials and paymentsSubscription & billingContract (6(1)(b)); legal obligation for tax/accounting records (6(1)(c))
Understand usage and improve the productUsage & analyticsConsent (Art. 6(1)(a)) — withdrawable at any time
Security, fraud/abuse prevention, debuggingAccount, technical, server logsLegitimate interests (Art. 6(1)(f))
Service emails (verification, billing, important notices)AccountContract (6(1)(b)) / legitimate interests

4. Who we share it with (processors)

We do not sell your personal data. We share it only with vendors who process it on our behalf under data-processing agreements:

  • Google / Firebase — authentication, database (Firestore), hosting, serverless functions, and (with consent) Google Analytics. Google LLC, USA.
  • Stripe — subscription billing and payment processing. Stripe, Inc. (USA) / Stripe Payments Europe (Ireland).
  • Cloudflare — DNS, content delivery and security; may process connection metadata (e.g. IP) to route and protect traffic. Cloudflare, Inc., USA.

We may also disclose data where required by law, or in connection with a merger or acquisition (with notice where required).

5. International transfers

Our processors are based in the United States, so your data may be transferred outside the EEA/UK. These transfers are covered by appropriate safeguards — the EU–US / UK Data Privacy Framework and/or the European Commission's Standard Contractual Clauses, as set out in Google's and Stripe's data-processing agreements.

6. How long we keep it

  • Account data — kept while your account is active and deleted immediately when you delete your account (Account → Privacy & your data), or shortly after we close it. Some records may be retained longer where required by law.
  • Billing records — retained for the period required by applicable tax law (currently at least 5 years under UAE VAT/tax record-keeping rules).
  • Analytics — retained per our Google Analytics configuration (currently 14 months).

7. Your rights

Under the GDPR you have the right to: access your data, rectify inaccuracies, request erasure, restrict or object to processing, receive a portable copy, and withdraw consent (for analytics) at any time without affecting prior processing.

To exercise these rights, email privacy@seneca-risk.com, or use the self-service export and delete account tools in your account settings. You also have the right to lodge a complaint with your local data-protection supervisory authority.

8. Cookies

We use a small number of essential cookies, and, only with your consent, Google Analytics cookies. Full details and controls are in our Cookie Policy.

9. Children

Seneca is intended for users aged 18 and over and is not directed to children. We do not knowingly collect their data.

10. Changes

We may update this policy; we will revise the “last updated” date and, for material changes, notify you by email or in-product.

11. Contact

Questions or requests: privacy@seneca-risk.com.

PrivacyTermsCookies Cookie settings