Legal
Privacy Notice
What personal data Seraph CTI (formerly PhishGuard) handles, why, who else sees it, how long we keep it, and what you can ask us to do about it. Written under Kenya’s Data Protection Act 2019.
Version 2026-08-14 · Effective 14 August 2026
Draft, pending legal review. This document describes what the platform does today and what we intend to commit to. It has not yet been reviewed by an advocate, and items marked [TO CONFIRM] are unresolved. If you are evaluating Seraph CTI for procurement, ask us for the reviewed version rather than relying on this one.
1Two kinds of people, two different roles
This matters more than it sounds, because our obligations differ.
If you signed up, or you administer an account, we are the data controller for your name, work email, organization and the record of what you did on the platform. This notice is our notice to you.
If your employer put you on Seraph CTI as a member of staff to be trained, your employer is the controller and we are their processor. We act on their instructions. Your rights are exercised against them, and we help them answer you — the terms are in the Data Processing Addendum. If you contact us directly, we will pass your request to your employer and tell you we have.
2Who we are
Seraph Cyber Limited, Enwealth Business Centre, Ngong Lane, Nairobi, Kenya. For anything in this notice, write to privacy@seraphcyber.com.
[TO CONFIRM: whether Seraph Cyber is registered with the Office of the Data Protection Commissioner, and its registration number]
3What we collect, and why
When you enquire or sign up: your name, work email, organization name and the headcount you told us, plus the IP address and browser the request came from. We keep the last two for abuse review, because a form that provisions accounts is worth being able to look back at. Our basis is taking steps to enter into a contract at your request, and our legitimate interest in preventing abuse.
When you use the platform as an administrator: your account details, your sign-ins including whether they used SSO or MFA, and the administrative actions you take. Our basis is performing the contract, and our legitimate interest in a security audit trail.
When we bill you: billing contact details, your KRA PIN where you give it, invoices, payments and their references. Our basis is performing the contract and complying with tax law.
Staff loaded by your employer: name, work email, department or group, and the record of how they responded to simulations and training. We process this on your employer’s instruction, not our own.
Breach-exposure monitoring, where your package includes it: we check staff addresses against breach and infostealer corpora. Recovered password values are read only to set an exposure flag and are discarded at the boundary — only the names of the exposed fields are stored. We never hold a recovered credential.
4What we do not do
We do not sell personal data. We do not use your data or your staff’s data to train machine-learning models. We do not run advertising on the platform, and we do not use third-party advertising or analytics trackers on it.
Reports your staff submit through the report button feed a regional threat picture shared with other customers. What is shared is the threat itself — the lure, the sending infrastructure, the technique. Your organization is not named and the reporter is not identified.
5Who else processes it
These are our sub-processors. Each receives only what its purpose needs, and the ones marked optional can be switched off without losing the core product.
| Who | For what | What reaches them | Where | Optional |
|---|---|---|---|---|
| Anthropic | AI-assisted template generation, analysis and reporting | Prompt content, which may include campaign and training material and the names of departments or roles | United States | Yes |
| Pesapal | Card and M-Pesa payment processing | Billing contact name and email, invoice reference and amount. Card details are entered on Pesapal’s own hosted page and never reach Seraph CTI. | Kenya | Yes |
| Have I Been Pwned | Breach exposure monitoring for your domains | Domain names and staff email addresses, queried against breach corpora | United States / Cloudflare edge | Yes |
| LeakCheck | Second breach-exposure source behind the same adapter | Domain names and staff email addresses. Recovered credential values are discarded at the boundary — only field names are stored. | [TO CONFIRM] | Yes |
| Email delivery | Platform mail: invitations, invoices, receipts, notifications | Recipient name and address, and the content of the message | [TO CONFIRM — the configured SMTP relay] | No |
| Hosting | Running the platform and storing its database and backups | All customer data | [TO CONFIRM] | No |
We also query public catalogues — NVD (vulnerability catalogue), CISA Known Exploited Vulnerabilities, VirusTotal, urlscan.io — for vulnerability and threat data. No personal data is sent to any of them, which is why they are not in the table above.
We will tell customers before adding a sub-processor that receives personal data.
6Where it is held
The platform and its backups run on [TO CONFIRM: hosting provider and the country its data centre is in].
Some sub-processors above are outside Kenya. Where personal data is transferred out of Kenya we rely on the safeguards in section 49 of the Data Protection Act, and we will provide details of the safeguard used on request.
7How long we keep it
These are the windows the platform actually enforces, by scheduled job. Where a window is configurable by the customer, the default is given.
| What | How long |
|---|---|
| Simulation and training records (clicks, opens, submissions, completions) | 365 days by default, configurable per organization |
| Audit log | 365 days by default, configurable per organization; exported to CSV before purge |
| Email delivery logs | 90 days |
| Unverified signup requests | Expire after 48 hours and are swept thereafter |
| Invoices, credit notes and payment records | Retained for the statutory tax period and not deleted on request — a tax record we are required to keep |
| A staff member erased at your request | Anonymized after a 30-day grace period, which exists so an erasure made in error can be recalled |
| A closed account | Purged 30 days after deletion is requested; exportable throughout that window |
8How it is protected
Encrypted in transit, hard tenant isolation enforced at the query layer, multi-factor authentication, passwords stored only as adaptive one-way hashes, API keys stored hashed and individually revocable, and an audit log of security-relevant events. The detail is on our Trust & Security page, which describes only things the platform actually does.
9Your rights
Under the Data Protection Act 2019 you may ask to see the personal data we hold about you, to have it corrected, to have it erased, to restrict or object to how we use it, and to receive it in a portable form. You may also complain to the Office of the Data Protection Commissioner.
Write to privacy@seraphcyber.com. We will respond within the statutory period. If you are a member of staff on a customer’s account, see clause 1 — we will route your request to your employer, which is the fastest way to get it answered.
Erasing a staff member anonymizes their records after a 30-day grace period. The grace exists so an erasure made in error can be recalled; after it, the anonymization cannot be undone. Invoices and payment records are not erased — we are required to keep them.
10Cookies
The marketing site sets no cookies and carries no third-party analytics or advertising trackers. The application behind sign-in uses only what is strictly necessary to keep you signed in and to protect the session. There is nothing here to opt out of, which is why you have not been shown a banner.
11Changes
Each version of this notice carries a version number and effective date at the top. If we make a material change we will tell account administrators before it takes effect.
Questions about any of this? Write to privacy@seraphcyber.com, or talk to us.