You are viewing the static copy of this page (scripts have not loaded). All content below is complete and current.
This policy explains how Demiurge Systems Ltd ("Demiurge Systems", "we", "us") handles personal data collected through demiurge.systems and the services we deliver. It reflects how the site and our intake systems actually work today.
Who we are
Demiurge Systems Ltd is a company registered in England (company number 17109558). We are the data controller for personal data processed through this website.
For any privacy question or to exercise your rights, contact us at ops@demiurge.systems or via the contact form at /contact.
Data we collect
We only collect what we need to respond to you and deliver our services:
- Enquiry & contact data — name, work email, company, role, phone (optional), industry, selected package, your message, preferred contact method and availability, submitted through our contact and package forms.
- Account & order data — where you purchase a package: email, billing details, and subscription records. Card details are entered directly with our payment processor and are never seen or stored by us.
- Technical data — standard server and delivery logs (e.g. IP address, timestamp, user agent) generated by our hosting and used for security, abuse-prevention, and reliability.
We do not run third-party advertising or behavioural-tracking analytics on this site, and we do not set non-essential cookies (see “Cookies”).
How we use data, and our lawful basis
- To respond to enquiries and provide the strategy call you request — lawful basis: your consent and our legitimate interest in responding to prospective customers.
- To provide, bill for, and support purchased services — lawful basis: performance of a contract.
- To secure the site, prevent abuse/spam, and keep records — lawful basis: legitimate interests.
- To meet legal, accounting, and tax obligations — lawful basis: legal obligation.
We do not sell personal data, and we do not use your enquiry content to train third-party AI models.
International transfers
Some of our providers are located in, or transfer data to, the United States and other countries outside the UK/EEA. Where that happens, transfers are covered by appropriate safeguards such as the providers’ Standard Contractual Clauses and equivalent mechanisms offered in their data-processing terms.
Retention
We keep enquiry and CRM records for as long as needed to deal with your request and for a reasonable follow-up period, then review and delete or anonymise them. Order and billing records are kept for the period required by law (typically six years for UK tax purposes). You can ask us to delete your data sooner (see “Your rights”).
Security
The site is served exclusively over HTTPS with HSTS. Payment card data is handled entirely by our PCI-DSS-compliant payment processor. Secrets and API keys are held in managed environment configuration, never in client code, and are redacted from any diagnostic output. See our Security page for the full list of implemented controls.
Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.
Your rights
Subject to law, you may request access to your data; correction; deletion; restriction or objection to processing; and portability. You may also withdraw consent at any time and complain to a supervisory authority (in the UK, the Information Commissioner’s Office).
To exercise any right, email ops@demiurge.systems or use /contact. We respond within statutory timeframes.
Changes to this policy
We may update this policy as our services change. The version and dates at the top of this page always reflect the current edition; material changes will be highlighted here.
Demiurge Systems Ltd · Registered in England · 17109558 · Document version 1.0.