Privacy and connected services
Privacy notice
This notice explains how the Seymore Consulting operating hub accesses, uses, stores and shares information when applicants, clients, Seymore team members, investors, investees and partners use the service, including people with more than one approved access category.
Last updated: 4 October 20261. Who operates the workspace
The workspace is operated by Seymore Consulting. Questions about privacy, consent or account access should be raised with your Seymore Consulting administrator through the portal.
Public funding applications
You can start a funding enquiry without a Google account or an existing client login. We receive the business and contact details, funding need, intended use, consent record and supporting documents you choose to provide. This information is applicant-provided and is not treated as verified financial information or a funding approval.
A private application credential is saved on your device for up to seven days. The server retains only its hash. It opens only your new application and its files; entering an existing client, staff or investor email does not give access to that person's account. On a shared device, close the application session when you finish. Keep the application reference and contact SC if you need help after the session expires.
Application records and review history are stored in the operating database; documents are held in private object storage. Authorised SC staff review the enquiry. A business record is linked or created only after an explicit staff identity review, with the original application and document provenance retained. Account verification and full client-portal assignment are separate steps. Applications are not automatically sent to capital providers. Submitted information remains subject to the retention and correction provisions below.
2. Information we receive
Depending on your access categories and the permissions you approve, the workspace may receive:
- Your assigned email, organisation domain, one-time account verification, password-security record, invitation and exact access categories and assignments. Passwords are stored only as hardened, salted password hashes; participants do not need a Google account.
- For authorised Seymore staff who choose to connect services, verified Google Workspace account name, email address, hosted-domain information and approved service permissions.
- Your organisation, mandate, client record and partner profile.
- Business information, funding requirements, insurance prompts, wealth fact-find prompts and supporting information entered by authorised users.
- Master Transaction Control data, including workstreams, current positions, evidence states, risks, owners, dependencies, actions, dates, decisions and source links.
- For partners, assigned referral names, stages, next actions, expected-receipt bases, forecast amounts and separately evidenced invoice or payment states.
- Google Drive file names, metadata and document contents that an authorised staff user asks the readiness engine to scan.
- For authorised Seymore team accounts only, Gmail and Calendar information used for evidence and follow-up signals.
- Documents a client or investee uploads directly into an assigned private case, including statements, identity, CIPC, financial, tax, address, contract and funding-support files.
- Publicly available company information returned by an on-demand, source-linked research request.
3. How Google user data is used
Google user data is used only for authorised Seymore team features: verify an SC staff identity, read specifically authorised evidence, connect internal operational signals, send an approved communication, or refresh a readiness result. It is not required for external participant login.
When an authorised staff member saves a Google connection, the app stores an encrypted refresh token on the server, together with the connected account, approved permissions and connection status. This lets the server obtain short-lived access tokens for authorised features without requiring the staff member to keep a browser open. Saving a connection does not by itself enable every background feature or authorise sending messages.
Short-lived access tokens are not stored in the operating database. A temporary browser-based Google connection may also be used for a staff-requested action. Disconnecting Google in the app removes its saved connection and pending authorisation, and attempts to revoke the Google authorisation. Staff can also revoke the app's access from their Google account.
Google Drive document contents are processed for the requested scan and are not stored as a document copy in the site database. Documents deliberately uploaded through the client dashboard are stored separately in private object storage; D1 stores their ownership and review metadata, not their file bytes.
4. Gmail, Calendar and Drive boundaries
Gmail, Calendar and wider Drive access is restricted to approved Seymore team accounts. Gmail send access is used only when an authorised staff user explicitly sends a role-tailored login invitation, signature request or human-reviewed communication from the app; the service does not alter calendar events or infer that a funding submission, insurance placement or investment transaction occurred merely because a message or document exists.
Where an authorised team member explicitly enables email evidence collection, the app reads only their selected existing Gmail label. It retains message and thread references, selected email headers, dates and attachment metadata in a private staff review inbox. This collector does not store message bodies or attachment bytes, change the mailbox, send messages, grant access or update client or mandate facts automatically. Pausing collection or disconnecting Google stops new collection; already saved evidence and its history remain subject to the retention provisions below.
Separately, an authorised SC staff member may choose an original email attachment, select its exact client and document type, and confirm saving it to that client's private document vault. The app records the original mailbox, message, thread and attachment reference alongside the saved document. Compatible byte-identical files are kept as one document rather than copied again. New files require document review; saving them does not verify their financial contents or approve funding. These deliberate copies and their source history remain subject to the same access, retention and correction controls as client uploads.
Drive access is used to inspect existing folders and files the connected staff account can access or to operate a managed internal SC workspace when a dedicated service identity is configured. Temporary Google Drive OCR copies may be created for image-based documents and are deleted immediately after text extraction. External client uploads use the app's private document vault instead of a participant's personal Drive.
5. What is stored
The site database stores the minimum operating information needed to provide the service, including business records, site-native MTCs and controls, investor mandates, partner profiles and assigned referrals, email-bound multi-category portal permissions, team presence, activity history, evidence counts, client-document ownership and review metadata, and confirmed or rejected enrichment states. Client-uploaded files and original email attachments deliberately saved by SC staff are held in private object storage and are available only through an authorised case-specific download. Sensitive extracted values such as identity numbers and personal contact details are not retained as enrichment facts.
6. Sharing
Information is not sold. It may be made available to authorised Seymore personnel, the invited investor, investee or partner whose dashboard it belongs to, and service providers required to host, secure or operate the workspace. A participant's score or commercial relationship never grants access to another participant's information.
Google user data is not used for advertising, credit scoring, unrelated profiling or training general-purpose artificial-intelligence models by Seymore Consulting.
7. Retention and deletion
Operating records are retained while they are needed for the client, mandate, regulatory, audit or business purpose for which they were collected. Access can be revoked by disabling the portal user, revoking its direct access credential, removing a relevant staff Google permission or contacting Seymore Consulting. A user may request access, correction or deletion subject to applicable legal and record-retention requirements.
8. Security and user control
Access is restricted by exact email, personal password, category and record assignment. One email may hold several categories inside one account, but one category never grants another automatically. The email domain is an additional organisation check only. Internal dashboards require an approved Seymore staff account; client, investor, investee and partner dashboards require an assigned account and completed one-time verification. Partner access is further limited to the partner profile and referrals explicitly assigned by the SC team. Users should not share passwords, setup codes, account sessions or confidential documents with unauthorised persons.
9. Google Limited Use disclosure
The workspace's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
10. Changes
This notice will be updated when the service or its use of Google user data materially changes. The date at the top identifies the current version.
