Seafarer Consulting LLC ("Seafarer", "we", "us") provides accounting services and an online client portal (the "Sea Portal"). This policy explains what personal information the Portal and our website handle, why, who else sees it, and how long we keep it. Questions: info@seafarerconsulting.com.
1. Who this policy covers
- Client users: people at a client business who are given access to the Portal.
- Seafarer staff: our employees and leadership.
- Visitors to our public website, including anyone who submits a contact or quote form.
Portal accounts are created by Seafarer, by invitation only. There is no public sign-up.
2. What we collect
2.1 What you or your organization give us
2.2 What we generate or retrieve to provide the service
2.3 What we deliberately do not collect
- Card and bank details. Payments run entirely through Stripe's hosted checkout. Card numbers never reach our systems; we store only Stripe's identifiers and the payment status.
- The contents of your email. We never ask you to connect your mailbox, and we cannot read it.
- Message bodies from our own shared inbox, as above.
- Special category data. The Portal is not designed to hold health, biometric, or similar sensitive data, and you should not upload it.
3. Why we use it
- To respond to your enquiry, prepare a quote, and schedule a consultation.
- To deliver the services in your engagement letter: closing your books, preparing statements and forecasts, filing returns, and advising you.
- To operate, secure, and support the Sea Portal, prevent unauthorized access, and keep audit records.
- To send service communications such as close reminders, document requests, and deadline notices.
- To send occasional updates and insights, only where you opted in. Every marketing email has an unsubscribe link.
- To bill and collect fees, to meet our legal and professional record-keeping obligations, and to improve reliability and fix faults.
We do not sell personal information, and we do not share it for advertising.
4. Your financial records
When we become your back office, your financial records stay yours. We hold them as a service provider, we use them only to perform the engagement, and we keep them confidential. We do not use client financial data to train third-party models, and we do not disclose your figures to anyone outside your engagement team without your instruction, unless the law requires it.
5. Automated decisions and AI
No automated decision produces a legal or similarly significant effect about you.
The Portal does not expose an AI assistant to client users. Where meeting transcripts are summarized, that summarization is performed by our meeting provider, the output is visible only to Seafarer staff, and any resulting action is created by a person who decided to create it. A person is always in the loop.
6. Who else processes your information
We use service providers ("subprocessors"), each bound by contract to process data only on our instructions. The providers that handle client financial records or meeting content are named:
We also use providers that do not hold your financial records, by category:
- Sign-in, session management, and multi-factor authentication
- Seafarer's own email and calendars
- Notification email delivery
- Error monitoring, configured so that text is masked and media is not captured
- Operational log storage
A full, current list including these providers is available on request. We will tell affected clients before adding a subprocessor that handles client financial records or meeting content.
Some providers operate outside the United States. Where information is transferred internationally we rely on the EU-US Data Privacy Framework, with Standard Contractual Clauses as a fallback, and we require appropriate safeguards.
7. Who can see what, inside Seafarer
Access is enforced by the system itself, not by policy alone:
- Client users see only the entities they have been granted, and only their own organization's data.
- Seafarer staff see only the clients they are assigned to. An unassigned employee has no access at all to a client's records, not reduced access.
- Leadership can access all client records and the separate folder holding employee contracts. Leadership access to documents is logged the same way as everyone else's.
- Meeting transcripts and internal notes are not visible to clients, including transcripts of the client's own meetings. These records hold our candid working assessments, and making them client-readable would destroy both their value and our candor.
Every document opened or downloaded is recorded, including refused attempts.
8. Security
- Encrypted in transit and at rest.
- Strong authentication is required for every account. Client and employee accounts require a passkey or an authenticator app; Leadership accounts require a passkey and an authenticator app. SMS codes are not used.
- Uploaded files are checked by content, not by filename. Malware scanning is being deployed as a gate on downloads, so that a file which has not passed scanning cannot be downloaded by anyone, at any permission level. Until that gate is live in production, please treat uploads as you would any file exchange and send only documents you trust.
- PDFs are stripped of active content before being served.
- Access is separated at the database level, so one client's records cannot be returned in another client's session.
- Independent security testing is carried out before real client data is onboarded.
Please send sensitive documents through the Sea Portal rather than by plain email. No system is perfectly secure. If a breach affects your information we will notify you and any required authority without undue delay.
9. How long we keep things
Accounting records may be subject to statutory retention periods that override the above.
10. Your rights
Depending on where you live, you may have the right to request access to your personal information, correct it, delete it, restrict or object to processing, receive a copy in portable form, or withdraw consent where we rely on it. We will not discriminate against you for exercising these rights.
To exercise any of these, email info@seafarerconsulting.com with the subject line "Privacy request." We verify identity before acting and respond within 30 days.
Two honest caveats:
- Some records we are legally required to retain as an accounting practice, and we cannot delete those on request until that period expires.
- Audit and access logs are deliberately immutable. They record who did what, and a log that could be edited would not be a record. We cannot amend them.
- Where we hold information as a service provider on behalf of a client, we will refer your request to that client.
12. Children
The Portal is a business tool and is not directed to anyone under 18. We do not knowingly collect information from children.
13. Changes
If we make a material change we will update the date at the top and notify Portal users before it takes effect.