Compliance & Trust

Data Residency

Last updated: 15 September 2026

Data Controller

Attomus Limited is the data controller for SemaFore under UK GDPR.

Organisation Details

  • Legal Name: Attomus Limited
  • Registered in: England and Wales
  • Company Number: 06517654
  • Address: 23 Berkeley Square, Mayfair, London W1J 6HE
  • Contact: hello@attomus.com
  • ICO Registration: ZA718457

Core residency position

SemaFore is built so that core service data stays inside the Attomus boundary except for the narrowly scoped platform functions listed below. This page describes the product runtime; the privacy notice separately covers the public website, support intake, and related processors.

Our server infrastructure runs from Attomus-operated facilities in Coventry, United Kingdom. The databases that hold account information, organisation membership, audit events, and encrypted message ciphertext are operated under Attomus control in the UK.

What stays inside the Attomus boundary

  • account identifiers such as phone number and display name
  • organisation and membership records
  • audit log entries
  • encrypted message ciphertext
  • encrypted file ciphertext

Mobile messages and files are encrypted on-device before transmission. Portal-admin broadcasts follow a separate path: the administrator’s browser fetches recipient-device key bundles through the portal and creates a distinct encrypted envelope for each device. The portal server rejects plaintext message fields, so only ciphertext envelopes cross the Cloudflare-hosted portal boundary and reach the core messaging server. The core server stores and routes ciphertext only and has no mechanism to read message content.

Narrow exceptions outside the Attomus boundary

The product runtime uses the following narrowly scoped external functions:

ServiceRoleData processed
Apple APNsiOS push deliveryDevice push token and routing identifiers only; no decrypted message content
Google Firebase Cloud MessagingAndroid push deliveryDevice push token and routing identifiers only; no decrypted message content
TwilioSMS OTP deliveryPhone number and OTP SMS body for sign-in delivery
Mailgun EUTransactional email deliveryRecipient email address, email body, and delivery metadata for evaluation, account, invitation, approval, portal-login, and security messages; no SemaFore message or file content
StripePaid-plan billingBilling identity and payment data for paid organisations
Cloudflare Pages, Workers, and edgePublic-site and portal hosting, TLS termination, DDoS protection, and portal-admin request routingNetwork metadata; portal session and administrative request data; ciphertext broadcast envelopes. Broadcast plaintext is encrypted in the administrator’s browser and rejected by the portal server boundary

Outside these functions, personal data does not leave the United Kingdom and does not leave Attomus.

Email and analytics

SemaFore sends transactional email through Mailgun’s EU service for evaluation and account setup, organisation invitations and approval requests, portal-admin login codes, and security notifications where those functions apply. SemaFore does not use third-party advertising, behavioural tracking, or data-broker services. The privacy notice describes the provider boundaries in detail.

Privacy Policy and Data Rights

  • Privacy Policy: https://semafore.io/privacy
  • Data Subject Rights: Contact hello@attomus.com with subject line “Data Rights — SemaFore” to request access, rectification, erasure, restriction, portability, or objection. Attomus will respond within 30 days.
  • ICO Complaints: Users may lodge complaints with the Information Commissioner’s Office at ico.org.uk.