Information handled
Severus may handle account information such as name, work email and authentication events; workspace content such as requests, approvals, comments, attachments and audit events; payment-routing information; and limited service telemetry used for security, reliability and support. The exact fields depend on the features configured by the workspace.
Sign-in, verification and account linking
You may sign in with a password or with a configured identity provider such as Google, Microsoft or Apple. For a provider sign-in, Severus receives the identity claims needed to authenticate you, such as a provider-scoped subject identifier, email address, verification status and, where supplied, your name. Severus does not receive your provider password. A provider identity is not silently merged with an existing password account just because the email address matches; linking is an explicit action by the authenticated account holder. We may also record MFA events, invitation context, recovery activity and session security signals.
Cookies and similar technologies
Severus uses essential cookies and related browser storage to maintain a signed-in session, protect authentication flows, preserve a safe return path and remember limited onboarding state. These technologies are necessary for the service and are not used to sell advertising profiles. Provider websites may set their own cookies when you leave Severus for an identity-provider sign-in; those cookies are governed by that provider's notice.
Why it is used
- To provide the workflows and integrations selected by the workspace.
- To authenticate users and enforce workspace roles.
- To deliver transactional notices and provider responses.
- To investigate security, reliability and support issues.
- To meet applicable legal and contractual obligations.
Roles and service providers
For customer workspace content, the customer generally determines the processing purpose and Severus processes the data to provide the service. Severus may act as controller for its own account, security, commercial and support records. Infrastructure, communications, payment and AI providers may process data where needed for configured features. The applicable subprocessor and transfer details are provided for the intended deployment before contracting or on request.
AI-assisted features
Snape may use workspace context to prepare, classify, summarise or route work when those features are enabled. Permissions and human approval gates still apply. Model providers, data locations, retention and training-use restrictions must be stated in the applicable deployment terms; this notice does not replace those commitments with a broader marketing claim.
Security and access control
Severus applies workspace membership, role and approval controls to user-visible work. Authentication transactions are short-lived and single-use, and provider identity tokens are checked against the configured issuer, audience, nonce, signature and authorization transaction. No online service can promise absolute security, so report suspected account or data issues promptly through the contact channels below.
Sharing
We do not sell personal information. Data may be disclosed to authorised workspace users, configured service providers, professional advisers, transaction parties, or public authorities where a valid legal basis requires it. Access should be limited to the purpose for which it was provided.
Retention and deletion
Retention depends on record type, workspace instructions, the customer agreement, security needs and applicable legal obligations. We do not publish an invented universal deletion window. Contact privacy support for the schedule that applies to a production workspace.
International processing
Depending on the deployment and configured integrations, information may be processed in Nigeria or another country where Severus, an authorised infrastructure provider or a configured service provider operates. The applicable customer agreement and data-processing schedule identify the relevant locations, safeguards and subprocessors for a production workspace.
Changes to this notice
We may update this notice as the service, law or processing arrangements change. The revision date above identifies the current public version. Material changes will be communicated through an appropriate service or account channel where required.
Your choices and rights
Depending on applicable law, individuals may request access, correction, deletion, restriction, portability, objection or review of an automated decision. Workspace content requests may need to be handled first by the organisation that controls the workspace. Email privacy@severus.ng with the workspace name and the right you want to exercise. Do not email identity documents until a private verification channel is provided.
Nigeria
Our Nigeria data-protection notice summarises rights under the Nigeria Data Protection Act 2023 and points to the Nigeria Data Protection Commission.