Skip to content
← Legal

Privacy Policy

How Demiurge Systems collects, uses, and protects personal data.

You are viewing the static copy of this page (scripts have not loaded). All content below is complete and current.

This policy explains how Demiurge Systems Ltd ("Demiurge Systems", "we", "us") handles personal data collected through demiurge.systems and the services we deliver. It reflects how the site and our intake systems actually work today.

Who we are

Demiurge Systems Ltd is a company registered in England (company number 17109558). We are the data controller for personal data processed through this website.

Our registered office address and, where applicable, data-protection fee registration are being finalised and will be published here once confirmed. Until then, contact us at ops@demiurge.systems for correspondence details.

For any privacy question or to exercise your rights, contact us at ops@demiurge.systems or via the contact form at /contact.

Data we collect

We only collect what we need to respond to you and deliver our services:

  • Enquiry & contact data — name, work email, company, role, phone (optional), industry, selected package, your message, preferred contact method and availability, submitted through our contact and package forms.
  • Account & order data — where you purchase a package: email, billing details, and subscription records. Card details are entered directly with our payment processor and are never seen or stored by us.
  • Technical data — standard server and delivery logs (e.g. IP address, timestamp, user agent) generated by our hosting and used for security, abuse-prevention, and reliability.

We do not run third-party advertising or behavioural-tracking analytics on this site, and we do not set non-essential cookies (see “Cookies”).

How we use data, and our lawful basis

  • To respond to enquiries and provide the strategy call you request — lawful basis: your consent and our legitimate interest in responding to prospective customers.
  • To provide, bill for, and support purchased services — lawful basis: performance of a contract.
  • To secure the site, prevent abuse/spam, and keep records — lawful basis: legitimate interests.
  • To meet legal, accounting, and tax obligations — lawful basis: legal obligation.

We do not sell personal data, and we do not use your enquiry content to train third-party AI models.

Who we share data with (processors)

We share personal data only with service providers who process it on our behalf, under contract, to run the services described above:

  • Vercel Inc. — Website hosting, edge CDN, serverless functions (US / global edge).
  • Stripe Payments Europe / Stripe, Inc. — Payment processing & subscription billing (EU / US).
  • HighLevel Inc. (GoHighLevel / LeadConnector) — CRM & contact management for enquiries (US).
  • Resend (Plus Five Five, Inc.) — Transactional & confirmation email delivery (US).
  • Supabase Inc. — Authentication & database for account records (EU / US).
  • Anthropic PBC — AI model access for delivered operator systems (where provisioned) (US).
  • Google LLC (Google Fonts) — Web font delivery (may receive requesting IP) (US / global).
  • unpkg (operated by Cloudflare, Inc.) — CDN delivery of the site’s JavaScript libraries (receives requesting IP) (US / global edge).

Each provider is permitted to use the data only to provide their service to us. We may also disclose data where required by law.

International transfers

Some of our providers are located in, or transfer data to, the United States and other countries outside the UK/EEA. Where that happens, transfers are covered by appropriate safeguards such as the providers’ Standard Contractual Clauses and equivalent mechanisms offered in their data-processing terms.

Retention

We keep enquiry and CRM records for as long as needed to deal with your request and for a reasonable follow-up period, then review and delete or anonymise them. Order and billing records are kept for the period required by law (typically six years for UK tax purposes). You can ask us to delete your data sooner (see “Your rights”).

Security

The site is served exclusively over HTTPS with HSTS. Payment card data is handled entirely by our PCI-DSS-compliant payment processor. Secrets and API keys are held in managed environment configuration, never in client code, and are redacted from any diagnostic output. See our Security page for the full list of implemented controls.

Cookies & analytics

This site does not set non-essential or advertising cookies and does not embed third-party analytics trackers. Where you proceed to checkout, our payment processor may set cookies on its own domain that are strictly necessary to complete and secure the payment. Web fonts are loaded from Google Fonts, and the site’s JavaScript libraries are loaded from the unpkg CDN (operated by Cloudflare); both may receive your IP address as part of serving those files. Both are listed on the Subprocessors page.

Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.

Your rights

Subject to law, you may request access to your data; correction; deletion; restriction or objection to processing; and portability. You may also withdraw consent at any time and complain to a supervisory authority (in the UK, the Information Commissioner’s Office).

To exercise any right, email ops@demiurge.systems or use /contact. We respond within statutory timeframes.

Changes to this policy

We may update this policy as our services change. The version and dates at the top of this page always reflect the current edition; material changes will be highlighted here.


Demiurge Systems Ltd · Registered in England · 17109558 · Document version 1.0.