We use cookies to improve your experience and analyse site traffic. By clicking "Accept", you consent to our use of analytics cookies. Privacy Policy

Privacy Policy

Effective Date: May 10, 2026 | Last Updated: May 10, 2026

1. Introduction

Welcome to SalesSynq ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our sales SaaS platform and related services (collectively, the "Service").

By using our Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Service.

2. Information We Collect

2.1 Information You Provide

  • Account information (name, email, company details)
  • Payment and billing information
  • Communication preferences
  • Support requests and feedback

2.2 Information We Collect Automatically

  • Usage data and analytics
  • Device information and IP addresses
  • Cookies and similar tracking technologies
  • Performance and error logs

2.3 Third-Party Integration Data

Our Service integrates with various messaging platforms and communication channels, including but not limited to:

  • WhatsApp Business API
  • Gmail/Google Workspace
  • Microsoft Outlook/Office 365
  • Slack
  • Telegram
  • SMS/Text messaging services
  • Social media messaging platforms
  • Customer relationship management (CRM) systems

When you connect these services to our platform, we may collect and process:

  • Message content, metadata, and attachments
  • Contact information from conversations
  • Conversation history and thread data
  • User identifiers and profile information
  • Timestamps and interaction patterns
  • Business account information and settings

2.4 Cookies and Google Analytics

We use Google Tag Manager (GTM) and Google Analytics (GA) to understand how visitors use our website (e.g. pages visited, device type, approximate location). Analytics run only if you accept analytics cookies via our cookie banner. If you decline, we do not load GTM or GA and no analytics data is collected from your visit.

When you accept cookies, Google may collect data such as IP address, browser and device information, and usage data. This is subject to Google's Privacy Policy. You can change your choice at any time by clearing site data or using a different browser; we will show the cookie banner again on your next visit if no consent is stored.

3. How We Use Your Information

We use the collected information to:

  • Provide, maintain, and improve our Service
  • Process transactions and manage billing
  • Send service-related communications
  • Provide customer support and respond to inquiries
  • Analyze usage patterns and optimize performance
  • Ensure security and prevent fraud
  • Comply with legal obligations
  • Facilitate communication between users and customers
  • Generate business insights and analytics
  • Personalize user experience and recommendations

4. Data Encryption and Security

4.1 Data Encryption Standards

We implement the following concrete encryption controls:

Data at Rest:

  • Field-level application encryption using AES-256-GCM with HMAC-SHA256 integrity (per RFC 5116) for sensitive Customer Data fields.
  • Versioned encryption keys with rotation support; key material is held in environment-scoped secret stores and never committed to source.
  • Backups are encrypted (Restic-managed) and verified by an automated weekly restore drill.
  • Storage-layer encryption-at-rest is enabled on the underlying disks by the hosting provider; deployments serving Customers with sovereign-cloud requirements can additionally enable OS-level LUKS encryption of the data partition.

Data in Transit:

  • TLS 1.2+ for all public web and API traffic; HSTS uses a 2-year max-age, includeSubDomains, and the preload directive. Browser preload-list inclusion is not claimed.
  • Strict Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, and Referrer-Policy headers set on every response.
  • Internal service-to-service traffic is mutually authenticated (mTLS) in production.
  • TLS certificates are issued by a public CA (Let's Encrypt) and rotated automatically.

4.2 Security Measures

  • Authentication: OAuth 2.0 / OpenID Connect SSO with Google and Microsoft (which carry the Customer's own MFA), and native TOTP-based MFA with self-service enrolment, recovery codes, and configurable hard-enforcement for password sign-in.
  • Layered tenant controls combine scoped queries, OpenFGA checks where configured, and repository argument/result validation for tenant-aware values when authenticated tenant context exists. Strict null-tenant handling is configurable.
  • Append-only audit log with periodic chain sealing; retained for 365 days by default.
  • Static application security testing (CodeQL) on every pull request; OWASP Dependency-Check (CVSS ≥ 7 fails the build); secret scanning (Gitleaks) on every commit.
  • Documented incident response procedure; we will notify the affected data controller without undue delay and, in any event, within 72 hours of becoming aware of a personal-data breach (GDPR Article 33).
  • Annual third-party penetration testing planned; vendor selection in progress, engagement target before the first paying Customer. The executive summary will be made available on request under NDA once delivered.

4.3 AI / LLM Processing of Customer Data

  • No SalesSynq training on Customer Data. We do not use Customer Data to train or fine-tune models. Provider-side handling remains governed by the enabled provider's contract and configured controls. An OpenAI Zero-Data-Retention request has been submitted, but approval is not claimed.
  • Data minimization. Supported AI paths apply common-pattern redaction before provider egress. Coverage and configured policy vary by path, and pattern matching can miss personal data; it is not complete anonymisation.
  • Provider metadata. The primary instrumented orchestration path attaches an opaque tenant identifier and requires tenant context. Other provider paths must be assessed separately; this is not a claim about every LLM call.
  • Decision-support boundary. Numeric scores use versioned deterministic logic when sufficient evidence exists. LLM output is suggested text on supported paths and is subject to path-specific validation and human review.
  • Preliminary EU AI Act posture. Our public disclosure describes intended transparency and oversight controls. Classification and compliance conclusions remain pending counsel review.

4.4 Data Residency

Production data for the Service is stored in data centers operated by our infrastructure provider. Where applicable, we offer (or are working to offer) deployment in EU regions for Customers with EU data-residency requirements. Where data is necessarily transferred outside the European Economic Area — for example, when an LLM sub-processor's regional endpoint is required — we rely on the safeguards set out in Section 8.

5. Data Sharing and Disclosure

5.1 Third-Party Service Providers

We may share your information with trusted third-party service providers who:

  • Host our infrastructure and services
  • Process payments and billing
  • Provide analytics and monitoring tools
  • Deliver customer support services
  • Integrate with messaging platforms

Where a provider processes Customer Personal Data on our behalf, the applicable sub-processor agreement sets data-protection and security obligations. Provider controls, locations and retention terms can differ; this policy does not assert that every provider implements identical technical controls.

5.2 Legal Requirements

We may disclose your information when required by law, including:

  • Court orders or legal proceedings
  • Government investigations
  • Compliance with applicable regulations
  • Protection of our rights and safety

6. Data Retention

We retain personal data only as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Default retention periods are:

Data categoryDefault retentionNotes
Customer account data (admin users, billing contacts)For the term of the Service, plus 30 days after account closureSubject to legal-hold extensions
Customer Data ingested from connected CRMs / mailboxesFor the term of the Service; deleted within 30 days of account closure on requestDSAR-driven deletion supported
Application audit logs (who-did-what)365 daysAppend-only, periodically chain-sealed
LLM response cacheUp to 1 hourCache key derived from a redacted prompt; not used as a long-term store
Backups (system level, encrypted)7 daily / 4 weekly / 6 monthly snapshotsRestic-managed; weekly automated restore drill
Backup copies of an offboarded Customer's dataCleared as the snapshots above roll off — up to 6 months for the monthly tierWe do not perform targeted erasure inside immutable encrypted snapshots; backup copies are not used to restore an offboarded tenant and expire on the standard cycle
Billing / tax recordsAs required by applicable tax law (typically 6–10 years)Retained for legal-compliance purposes only

You may request deletion of your personal data at any time, subject to legal and contractual constraints, by contacting us at the address in Section 12 or by exercising the data-subject request flow inside the Service.

7. Your Rights and Choices

7.1 Access and Control

You have the right to:

  • Access your personal information
  • Correct inaccurate or incomplete data
  • Request deletion of your data
  • Export your data in a portable format
  • Opt-out of certain communications
  • Restrict or object to processing

7.2 Communication Preferences

You can manage your communication preferences through your account settings or by contacting our support team.

7.3 Third-Party Integrations

You control which third-party services connect to our platform. You can:

  • Revoke access to connected services
  • Modify integration permissions
  • Delete integration data
  • Control data sharing preferences

7.4 Cookie Consent and Analytics

You can accept or decline analytics cookies (including Google Analytics) using the cookie banner shown on your first visit. If you previously accepted and wish to opt out, clear this site's data in your browser or decline when the banner is shown again. Declining analytics cookies means we do not load Google Tag Manager or Google Analytics for your visits.

8. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers, including:

  • Standard contractual clauses
  • Adequacy decisions
  • Binding corporate rules
  • Other approved transfer mechanisms

9. Children's Privacy

Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you become aware that a child has provided us with personal information, please contact us immediately.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by:

  • Posting the new Privacy Policy on our website
  • Sending email notifications to registered users
  • Displaying prominent notices in our Service

Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.

11. Compliance Posture

We use the following laws as design and control-mapping references while readiness work and legal review remain in progress:

  • EU General Data Protection Regulation (Regulation (EU) 2016/679)
  • California Consumer Privacy Act (CCPA / CPRA)
  • EU Artificial Intelligence Act — Article 50 (transparency obligations for limited-risk AI systems); see our AI Disclosure

We are not currently certified to SOC 2, ISO/IEC 27001, or HIPAA. SOC 2 readiness is in progress; no attestation or completion date is claimed. Available readiness evidence can be discussed under NDA.

12. Contact Information

If you have questions about this Privacy Policy or our data practices, please contact us:

General privacy inquiries

SalesSynq

Email: [email protected]

Web: https://salesynq.com

Postal address: available on written request to the email above

Security or vulnerability disclosures: see /.well-known/security.txt

13. Complaints and Dispute Resolution

If you have concerns about our data practices, you may:

  • Contact our support team directly
  • File a complaint with relevant data protection authorities
  • Seek resolution through alternative dispute resolution mechanisms

We are committed to addressing all privacy concerns promptly and fairly.