Privacy Policy
Last updated: 29 July 2026
1. Introduction
DeepSeer Ltd ("DeepSeer", "we", "us", "our") is committed to protecting personal data and being straightforward about what we do with it.
This policy explains what personal data we collect, why, who we share it with, where it goes and what rights you have. It applies to:
- visitors to deepseer.ai and any subdomain;
- people who contact us, subscribe to our communications, or apply for a role with us;
- individuals at our customers and prospective customers who administer, use or evaluate the DeepSeer LLM Intelligence service (the "Service");
- individuals whose personal data appears in the outputs of the Service (see Section 2.3).
The Service is sold only to businesses and is not intended for use by anyone under 18. We do not knowingly collect personal data from children.
If you need this policy in an alternative accessible format, large print, plain text or audio, email support@deepseer.ai and we will provide one.
Please read this alongside our Cookie Policy, Terms of Service, Data Processing Addendum and Subprocessor List.
2. The roles we play
2.1 Where we are a controller
We decide why and how personal data is processed, and this policy governs it, for: website visitors and cookie data; enquiries, sales conversations and marketing; account administration for the Service; billing and payment contacts; job applicants; and our own suppliers and professional contacts.
2.2 Where we are a processor
Our customer decides why and how, and their instructions and our contract govern it, not this policy, for content a customer submits to the Service, the queries run on their instruction, and the outputs generated from them.
That processing is governed by our Data Processing Addendum, which forms part of our Terms of Service and applies automatically to every customer. If your data is processed by us as a processor, direct your request to the customer who is the controller. If you contact us instead, we will forward your request to them and tell you we have done so.
2.3 Personal data in the outputs of the Service
The Service queries third-party large language models, currently ChatGPT (OpenAI), Claude (Anthropic), Gemini (Google), Grok (xAI) and Perplexity, to analyse how a customer's brand, products, leadership and strategy are represented in those models' outputs, and reports the results back to the customer. Customers define stakeholder personas that shape those queries. Personas are analytical archetypes, for example "a sceptical institutional investor" or "a sector regulator", constructed by the customer. They are not, and must not be, profiles of named individuals.
Because customers may ask how their named senior executives are represented, Service outputs can contain personal data about identifiable individuals. Our position on that:
- We are the processor and the customer is the controller. The customer decides whose representation is analysed and is responsible for informing them and for having a lawful basis. Our contract requires it.
- We do not control what a model returns. Outputs may be inaccurate or out of date, and may incidentally contain special category data, an assertion about someone's political affiliation, health or religion, for example. Such content is a report of what a model said, not a statement of fact by DeepSeer, and we do not use it for any purpose beyond delivering it to the customer. Our contract requires customers not to use it to make decisions about individuals.
- We provide a route to have it removed. If personal data about you appears in a Service output, email support@deepseer.ai. We will identify the customer controller, notify them, and where we are permitted to act we will delete or suppress the material.
- Customers must not use the Service to analyse individuals with whom they have no relationship, including personnel of other organisations, journalists, regulators, elected officials and private individuals. This is a contractual prohibition, and where we become aware of a breach we suspend access.
3. Who we are and how to contact us
Legal entity: DeepSeer Ltd (registered as DEEPSEER LIMITED), registered in England and Wales, company number 12647524. Registered office: 71-75 Shelton Street, London, Greater London, WC2H 9JQ, United Kingdom.
We have appointed a data privacy manager responsible for overseeing questions about this policy. Contact them at support@deepseer.ai.
4. Personal data we collect
4.1 Categories
| Category | What it includes |
|---|---|
| Identity data | First and last name, job title, employer, username |
| Contact data | Business email address, telephone number, business postal address |
| Account data | Login credentials (passwords stored hashed), authentication identifiers where you sign in with Google, account role and permissions, preferences |
| Billing data | Billing contact name and email, billing address, VAT number, subscription and invoice history. We do not receive or store full payment card numbers, these go directly to Stripe |
| Technical data | IP address, browser type and version, operating system and platform, device identifiers, time zone, referring URLs |
| Usage data | Pages visited, features used, queries run, reports generated, timestamps, session and error logs |
| Communications data | The content of emails, support tickets, demo requests and meeting notes, and your marketing preferences |
| Recruitment data | CV, employment and education history, right-to-work information, and anything else you send us when applying for a role |
Customer content submitted to the Service, and the outputs generated from it, is handled under our Data Processing Addendum. See Sections 2.2 and 2.3.
4.2 Special category and criminal offence data
We do not seek special category personal data under Article 9 UK GDPR: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation. Please do not send it to us. Where it reaches us unsolicited we delete it, unless we are required to keep it. We cannot guarantee that such data will never appear in a model's output about a named individual; Section 2.3 explains how we handle that.
We do not routinely process criminal offence data. We may process it incidentally when investigating suspected fraud or unauthorised access to our systems, or in connection with legal claims.
4.3 Aggregated data
We produce aggregated, de-identified statistics, for example the proportion of accounts using a given feature. Where that data cannot reasonably be used to identify anyone it is not personal data, and we may use it for any purpose. If we combine it back with personal data, we treat the result as personal data.
5. How we collect it
- Directly from you, when you complete a form, request a demo, correspond with us, create or administer an account, subscribe to updates, apply for a role, or meet us at an event.
- Automatically, through cookies and similar technologies. See our Cookie Policy. Non-essential cookies are set only with your consent.
- From your organisation, where a colleague with administrative rights creates an account for you.
- From third parties, analytics data from Google Analytics where you have consented, and billing status from Stripe.
- From publicly available and commercial sources, business contact details (name, job title, employer, business email) from professional sources and business-contact data providers, used solely to contact organisations about the Service. Every message carries a one-click opt-out, and you can ask us to identify the source at any time.
6. Why we use it, and our lawful basis
| Purpose | Data used | Lawful basis |
|---|---|---|
| Providing the Service: creating and administering accounts, authenticating users, supporting customers, and sending service notifications | Identity, Contact, Account, Usage, Communications | Performance of a contract |
| Processing subscriptions and invoicing | Identity, Contact, Billing | Performance of a contract |
| Recovering sums owed to us | Identity, Contact, Billing | Legitimate interests (recovering debts properly due) |
| Responding to enquiries from people who are not customers | Identity, Contact, Communications | Legitimate interests (responding to people who contact us) |
| Securing our systems and preventing, detecting and investigating fraud, abuse and unauthorised access | Technical, Usage, Account | Legitimate interests (protecting our business, our customers and our systems) |
| Maintaining, debugging and improving the Service and the website | Technical, Usage | Legitimate interests (operating a product our customers rely on) |
| Website and product analytics | Technical, Usage | Consent, via the cookie banner |
| Marketing to corporate business contacts about the Service | Identity, Contact, Communications | Legitimate interests (business-to-business marketing), subject to your right to object at any time |
| Marketing to sole traders and unincorporated partnerships | Identity, Contact, Communications | Consent |
| Assessing job applicants | Recruitment, Identity, Contact | Legitimate interests (assessing candidates for roles we are recruiting) |
| Meeting legal, tax, accounting and regulatory obligations, including notifying you of changes to this policy | Any of the above as required | Legal obligation |
| Establishing, exercising or defending legal claims, and corporate transactions such as a merger or sale of assets | Any of the above as required | Legitimate interests (protecting our legal position and conducting corporate transactions) |
Each purpose has one lawful basis.
Marketing. We market only to business contacts, about the Service. Under PECR we treat sole traders and unincorporated partnerships as individual subscribers and market to them only with consent; purchased lists are screened accordingly. Opt out at any time using the link in any message or by emailing support@deepseer.ai. Opting out does not stop service notifications, which are necessary to operate your account. We do not sell your personal data and we do not share it with third parties for their own marketing.
If you don't provide it. Where we need personal data to perform a contract, name, business email and billing details, we cannot provide the Service without it. Everything else is optional and we will say so at the point of collection.
7. Who we share it with
Suppliers and subprocessors acting on our instructions. Our current list, who they are, what they do, where they are located and the safeguard relied on for each, is at deepseer.ai/subprocessors. That page distinguishes suppliers who process data on our behalf as a controller, such as hosting and analytics, from subprocessors engaged in providing the Service to customers, such as the large language model providers. We give at least 30 days' notice of changes to the latter, as set out in our DPA. Each is bound by a written contract, processes data only on our instructions, applies appropriate security and is subject to confidentiality obligations. We do not permit them to use personal data for their own purposes.
Recipients acting as independent controllers. Some organisations determine their own purposes and are responsible for their own compliance. We do not control what they do:
- Stripe, our payment processor, which acts as an independent controller for fraud prevention, anti-money-laundering and regulatory reporting under its own terms.
- Professional advisers: lawyers, accountants, auditors, insurers and bankers, in respect of their own regulatory and professional obligations.
- Authorities: HM Revenue & Customs, regulators, courts and law enforcement, where we are required by law to disclose or where disclosure is necessary in connection with legal claims. Where we are lawfully able to notify you of such a request, we will.
Acquirers. If we sell, merge or reorganise all or part of our business, personal data may transfer to the counterparty, who must continue to protect it consistently with this policy.
8. International transfers
Our hosting is in the United Kingdom. Customer content and account data are stored at rest in a London data centre region.
We do transfer some personal data outside the United Kingdom, principally to the United States. This is unavoidable in providing the Service: the large language models we query and our payment processor are operated by companies established in the United States. Every supplier and subprocessor we transfer data to routinely is named on our Subprocessor List, with its location and the safeguard relied on.
Where a recipient holds a current, active self-certification to the UK Extension to the EU-US Data Privacy Framework, we rely on that adequacy, and maintain contractual safeguards as a fallback. Otherwise we rely on the ICO's International Data Transfer Agreement (IDTA) or the ICO's International Data Transfer Addendum to the European Commission's Standard Contractual Clauses. We assess and document the risk of each transfer that relies on contractual safeguards, and keep those assessments under review.
Occasional transfers to professional advisers, or in the context of a corporate transaction, are not routine and may instead rely on the derogations in Article 49 UK GDPR.
You may request a copy of the safeguards we have in place by emailing support@deepseer.ai. We will provide a copy with commercially confidential terms redacted.
9. Artificial intelligence and model training
Because the Service is built on third-party AI models, we state our position explicitly.
- We do not use your personal data, your account content or your queries to train, fine-tune or improve any artificial intelligence or machine learning model, whether our own or a third party's.
- We do not sell personal data, and we do not share it for cross-context behavioural advertising.
- The Service does not make automated decisions producing legal or similarly significant effects about individuals, within the meaning of the UK GDPR.
- Outputs generated by large language models can be incomplete, out of date or wrong. Section 2.3 explains what that means for individuals named in them.
10. How long we keep it
| Data | Retention |
|---|---|
| Account and profile data | Life of the account, then 12 months after closure |
| Customer content processed under the DPA | Per the DPA, deleted or returned within 30 days of termination |
| Billing, invoicing and tax records | 6 years from the end of the accounting period, as UK tax law requires |
| Support tickets, correspondence and marketing contact data | 24 months from last contact, or until you opt out |
| Website analytics and security logs | Up to 14 months for analytics; 12 months for security and access logs |
| Unsuccessful job applications | 6 months after the process concludes, unless you agree to longer |
Where the law requires us to keep data longer, or we need it to establish, exercise or defend a legal claim, we will. Otherwise we delete it or irreversibly anonymise it. If you join us as an employee or contractor, your recruitment data transfers to your personnel file and is governed by our staff privacy notice.
11. Security
We apply technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, role-based access control, multi-factor authentication on administrative accounts, access logging and monitoring, vulnerability management and patching, backups and documented disaster recovery, confidentiality undertakings and data protection training for personnel, and contractual security obligations on our suppliers. The measures applicable to customer content are set out in Annex 2 of our Data Processing Addendum.
We have a documented incident response procedure. We notify the Information Commissioner's Office and affected individuals of a personal data breach where the law requires it, and we notify affected customers in accordance with our DPA.
No system is perfectly secure, and data sent over the internet is never entirely risk-free.
12. Your rights
12.1 What you can ask for
You have the right to: be informed about how we use your data, which is what this policy is for; access the personal data we hold about you; have inaccurate or incomplete data corrected; have data erased where there is no good reason for us to keep processing it; restrict processing in certain circumstances; object to processing based on our legitimate interests on grounds relating to your particular situation, and to object to direct marketing at any time, absolutely; receive data you provided in a portable format where processing is based on consent or contract and carried out by automated means; and withdraw consent at any time where we rely on it, without affecting processing carried out beforehand.
These rights are not all absolute and some have exceptions. If we cannot comply with a request, we will tell you why.
12.2 How to exercise them
Email support@deepseer.ai, or write to the data privacy manager at the address in Section 3.
We do not charge a fee unless a request is vexatious or excessive, in which case we may charge a reasonable fee or refuse it. We may ask for information to verify your identity, or to clarify what you are looking for where we hold a large volume of data about you.
We respond within one month of receiving your request, or of receiving the information we need to verify your identity or clarify the request, whichever is later. If a request is complex or you have made several, we may extend by up to two further months and will tell you within the first month. We conduct a reasonable and proportionate search.
12.3 Complaints
You have the right to complain to us. Email support@deepseer.ai. We will acknowledge your complaint within 30 days and take appropriate steps to respond without undue delay.
You also have the right to complain to the Information Commissioner's Office at any time, whether or not you complain to us first: ico.org.uk, 0303 123 1113.
13. Cookies
We use essential cookies to operate the website, functional cookies to remember your preferences, and analytics cookies to understand how the website and Service are used. Non-essential cookies are set only where you consent. Withdrawing consent is as easy as giving it: a "Cookie preferences" link in the footer of every page lets you change or withdraw your choice at any time. Full details, including a table of every cookie we set, are in our Cookie Policy.
14. Third-party websites
Our website and the Service contain links to third-party sites, and the Service reports on content originating from third parties. We do not control those sites and are not responsible for their privacy practices. Read their policies.
15. Changes to this policy
We keep this policy under review and update it when our practices change. The date at the top shows when it was last revised. Where changes are material we notify account administrators by email at least 30 days before they take effect.
16. Contact
DeepSeer Ltd, 71-75 Shelton Street, London, Greater London, WC2H 9JQ, United Kingdom. Company number 12647524.
- Privacy enquiries, rights requests and complaints: support@deepseer.ai
- Data Processing Addendum and contractual matters: legal@deepseer.ai
- Everything else: hello@deepseer.ai