Legal

Privacy Policy

Perseids holds ownership records, private transaction workflows and confidential company information. This policy describes what we collect, why we hold it, and who can see it.

Last updated 2026-08-13

Information you provide

Depending on how you use Perseids, we process:

  • Account information — name, email address, authentication credentials and workspace memberships.
  • Company information — entity details, stakeholders, security classes, transactions, options, warrants, convertibles and governance records.
  • Investor organisation information — organisation details, members, holdings and portfolio records.
  • Partner organisation information — organisation details, capabilities, jurisdictions and verification materials you submit.
  • Portfolio information — reported and connected holdings, valuations and provenance.
  • Uploaded documents — agreements, certificates and supporting files.
  • Workflow data — deal rooms, secondary workflows, invitations, approvals, comments and audit history.
  • Billing information — plan, subscription state, billing contact and invoice records.
  • Communications — messages you send us and transactional messages we send you.

Payment-card details are handled by our payment provider. Perseids does not receive or store card numbers.

Connected-company information

Investors do not receive a company’s ownership data by default. Company information reaches an investor workspace only through a verified relationship, a disclosure the company explicitly enables, and the permissions configured by that company. Companies can change or withdraw disclosure.

Where an investor sees figures derived from a company’s ledger, those figures are projected under the company’s disclosure settings — not by granting access to the underlying cap table.

Artificial intelligence

  • AI features assist with analysis, summaries and proposals.
  • AI is given only data the requesting user and workspace are already authorised to access.
  • AI cannot change the authoritative ownership ledger. Proposals are inert until a person with the right permission approves them.
  • AI output is analytical assistance and can be wrong. It is not legal, tax or investment advice.

AI requests are processed by AI infrastructure providers acting on our instructions. We do not make claims about third-party retention or model training beyond what our provider agreements actually guarantee.

Documents

Uploaded documents are private, tenant-scoped and access-controlled. They are readable only by members of the owning workspace who hold the relevant permission, and by counterparties where a document is explicitly shared through a workflow.

Billing

Subscription payments are processed by Paddle, which acts as the payment provider and merchant of record for the current integration. Paddle handles payment collection, applicable tax handling and the billing portal. Perseids stores the resulting subscription state and entitlements.

Transactional email

Service messages — invitations, approvals, workflow notifications and billing notices — are delivered through Postmark. Marketing email is separate and is not sent through the transactional channel.

Service providers

We rely on a small set of providers to operate the platform:

  • Application hosting and content delivery.
  • Managed PostgreSQL database, authentication and file storage.
  • Transactional email delivery.
  • Payment processing and subscription billing.
  • AI infrastructure for assistant and analysis features.

Providers process data on our instructions and for the purposes described here.

Security

Protections in place today include:

  • Authenticated access with per-workspace membership.
  • A role and permission model enforced on the server.
  • Tenant isolation enforced at the database level through row-level security.
  • Audit trails for sensitive actions.
  • Encrypted HTTPS transport.
  • Private, access-controlled document storage.

We describe the controls we actually operate. Perseids does not hold ISO 27001, SOC 2 or GDPR certification, and we do not claim any certification we have not obtained.

Retention

Account and workspace data is retained while the workspace is active. Some records must be retained longer: ownership records, completed equity transaction history, approvals and audit entries form part of the authoritative record of a company’s capitalisation and may be needed for audit, compliance, statutory obligations or dispute resolution.

Completed equity transaction history is not freely erasable. Where the law grants a deletion right, it is applied to the extent it does not defeat the integrity of the ownership record or an overriding legal obligation.

Your rights and how to reach us

Subject to applicable law, you may request access to your personal data, correction, deletion, a copy in a portable form, or restriction of certain processing. Where Perseids processes information on behalf of a company, investor or partner organisation, we will direct the request to that organisation.

Privacy enquiries: privacy@perseids.ai

Data controller and contracting entity: Perseids Ltd, a company incorporated in England and Wales.