Skip to content

Legal

Privacy Notice

What personal data Seraph CTI (formerly PhishGuard) handles, why, who else sees it, how long we keep it, and what you can ask us to do about it. Written under Kenya’s Data Protection Act 2019.

Version 2026-08-14 · Effective 14 August 2026

Draft, pending legal review. This document describes what the platform does today and what we intend to commit to. It has not yet been reviewed by an advocate, and items marked [TO CONFIRM] are unresolved. If you are evaluating Seraph CTI for procurement, ask us for the reviewed version rather than relying on this one.

1Two kinds of people, two different roles

This matters more than it sounds, because our obligations differ.

If you signed up, or you administer an account, we are the data controller for your name, work email, organization and the record of what you did on the platform. This notice is our notice to you.

If your employer put you on Seraph CTI as a member of staff to be trained, your employer is the controller and we are their processor. We act on their instructions. Your rights are exercised against them, and we help them answer you — the terms are in the Data Processing Addendum. If you contact us directly, we will pass your request to your employer and tell you we have.

2Who we are

Seraph Cyber Limited, Enwealth Business Centre, Ngong Lane, Nairobi, Kenya. For anything in this notice, write to privacy@seraphcyber.com.

[TO CONFIRM: whether Seraph Cyber is registered with the Office of the Data Protection Commissioner, and its registration number]

3What we collect, and why

When you enquire or sign up: your name, work email, organization name and the headcount you told us, plus the IP address and browser the request came from. We keep the last two for abuse review, because a form that provisions accounts is worth being able to look back at. Our basis is taking steps to enter into a contract at your request, and our legitimate interest in preventing abuse.

When you use the platform as an administrator: your account details, your sign-ins including whether they used SSO or MFA, and the administrative actions you take. Our basis is performing the contract, and our legitimate interest in a security audit trail.

When we bill you: billing contact details, your KRA PIN where you give it, invoices, payments and their references. Our basis is performing the contract and complying with tax law.

Staff loaded by your employer: name, work email, department or group, and the record of how they responded to simulations and training. We process this on your employer’s instruction, not our own.

Breach-exposure monitoring, where your package includes it: we check staff addresses against breach and infostealer corpora. Recovered password values are read only to set an exposure flag and are discarded at the boundary — only the names of the exposed fields are stored. We never hold a recovered credential.

4What we do not do

We do not sell personal data. We do not use your data or your staff’s data to train machine-learning models. We do not run advertising on the platform, and we do not use third-party advertising or analytics trackers on it.

Reports your staff submit through the report button feed a regional threat picture shared with other customers. What is shared is the threat itself — the lure, the sending infrastructure, the technique. Your organization is not named and the reporter is not identified.

5Who else processes it

These are our sub-processors. Each receives only what its purpose needs, and the ones marked optional can be switched off without losing the core product.

Seraph CTI sub-processors
WhoFor whatWhat reaches themWhereOptional
AnthropicAI-assisted template generation, analysis and reportingPrompt content, which may include campaign and training material and the names of departments or rolesUnited StatesYes
PesapalCard and M-Pesa payment processingBilling contact name and email, invoice reference and amount. Card details are entered on Pesapal’s own hosted page and never reach Seraph CTI.KenyaYes
Have I Been PwnedBreach exposure monitoring for your domainsDomain names and staff email addresses, queried against breach corporaUnited States / Cloudflare edgeYes
LeakCheckSecond breach-exposure source behind the same adapterDomain names and staff email addresses. Recovered credential values are discarded at the boundary — only field names are stored.[TO CONFIRM]Yes
Email deliveryPlatform mail: invitations, invoices, receipts, notificationsRecipient name and address, and the content of the message[TO CONFIRM — the configured SMTP relay]No
HostingRunning the platform and storing its database and backupsAll customer data[TO CONFIRM]No

We also query public catalogues — NVD (vulnerability catalogue), CISA Known Exploited Vulnerabilities, VirusTotal, urlscan.io — for vulnerability and threat data. No personal data is sent to any of them, which is why they are not in the table above.

We will tell customers before adding a sub-processor that receives personal data.

6Where it is held

The platform and its backups run on [TO CONFIRM: hosting provider and the country its data centre is in].

Some sub-processors above are outside Kenya. Where personal data is transferred out of Kenya we rely on the safeguards in section 49 of the Data Protection Act, and we will provide details of the safeguard used on request.

7How long we keep it

These are the windows the platform actually enforces, by scheduled job. Where a window is configurable by the customer, the default is given.

Retention periods
WhatHow long
Simulation and training records (clicks, opens, submissions, completions)365 days by default, configurable per organization
Audit log365 days by default, configurable per organization; exported to CSV before purge
Email delivery logs90 days
Unverified signup requestsExpire after 48 hours and are swept thereafter
Invoices, credit notes and payment recordsRetained for the statutory tax period and not deleted on request — a tax record we are required to keep
A staff member erased at your requestAnonymized after a 30-day grace period, which exists so an erasure made in error can be recalled
A closed accountPurged 30 days after deletion is requested; exportable throughout that window

8How it is protected

Encrypted in transit, hard tenant isolation enforced at the query layer, multi-factor authentication, passwords stored only as adaptive one-way hashes, API keys stored hashed and individually revocable, and an audit log of security-relevant events. The detail is on our Trust & Security page, which describes only things the platform actually does.

9Your rights

Under the Data Protection Act 2019 you may ask to see the personal data we hold about you, to have it corrected, to have it erased, to restrict or object to how we use it, and to receive it in a portable form. You may also complain to the Office of the Data Protection Commissioner.

Write to privacy@seraphcyber.com. We will respond within the statutory period. If you are a member of staff on a customer’s account, see clause 1 — we will route your request to your employer, which is the fastest way to get it answered.

Erasing a staff member anonymizes their records after a 30-day grace period. The grace exists so an erasure made in error can be recalled; after it, the anonymization cannot be undone. Invoices and payment records are not erased — we are required to keep them.

10Cookies

The marketing site sets no cookies and carries no third-party analytics or advertising trackers. The application behind sign-in uses only what is strictly necessary to keep you signed in and to protect the session. There is nothing here to opt out of, which is why you have not been shown a banner.

11Changes

Each version of this notice carries a version number and effective date at the top. If we make a material change we will tell account administrators before it takes effect.

Questions about any of this? Write to privacy@seraphcyber.com, or talk to us.