Privacy Policy
Updated: 2026-09-17
1 Who is responsible and what this policy covers
Sellforte Solutions Oy, business ID 2832424-2, Otakaari 5, 02150 Espoo, Finland, is responsible for personal data processed through our public websites and demo. Contact us at privacy@sellforte.com.
This policy covers visitors to sellforte.com, our support center and demo.sellforte.com; prospective customers; event participants; and people who communicate with us or represent customers, suppliers, and partners. Our group companies, including Sellforte, Inc., Sellforte Solutions GmbH, and Sellforte Solutions UK Ltd, may also process business contact and relationship information for their own dealings with you. The relevant company is identified in those dealings; the contact above can help with requests concerning any group company.
Use of a customer's production service is covered by the applicable service privacy notice, including the Online Service Privacy Notice where applicable. Processing on a customer's behalf follows that customer's agreement and DPA. This public-site policy does not replace those arrangements. Job applicants should use the Careers Privacy Policy.
2 Information we collect and why
We receive information from you and your interactions with us, from your organization, from public professional sources and company registers, and from business-contact, event, marketing, and advertising partners. Depending on the interaction, we process:
- Contact and relationship information: name, work contact details, company, role, correspondence, requests, meetings, proposals, agreements, and billing information. We use this to answer inquiries, arrange demonstrations, manage business relationships, and administer agreements. Our legal basis is our legitimate interest in running and developing our business; contractual necessity applies where you personally are party to the contract, and legal obligations apply to records such as invoices.
- Public demo interactions: prompts, responses, feedback, session and feature interactions, and related technical information. We use these to provide the demo and requested responses, troubleshoot errors, prevent misuse, and assess and improve the demo. Providing the requested demo is based on the demo contract with you where applicable; security and proportionate troubleshooting and improvement rely on our legitimate interests. Optional device tracking remains subject to consent as explained below.
- Technical and security information: IP address, request times, browser and device information, pages or features accessed, identifiers, and error and security events. We use necessary records to deliver and protect the sites, diagnose problems, and investigate misuse, based on our legitimate interests in a functioning and secure service.
- Analytics and advertising information: page views, referral and campaign information, interactions, cookie or similar identifiers, approximate location, and inferred company or professional interests. We use this to measure usage and campaigns, understand business interest, and show or measure advertising. We obtain consent for optional cookies and similar device access. Business prospect research from other lawful sources relies on our legitimate interest in relevant business marketing, subject to your right to object and any consent required by law.
- Marketing preferences and communications: subscriptions, consent records, delivery and interaction information, and opt-outs. We send marketing with consent where required, or based on legitimate interests where the law permits business marketing. We keep suppression records to respect objections and comply with our obligations.
- Events, surveys, and meetings: registration details, professional interests, responses, and information you choose to provide. We use these to organize events and respond to feedback, based on legitimate interests or consent where required. We inform participants before recording or transcribing a meeting and obtain consent where required. Do not provide sensitive information unless specifically requested through an appropriate process.
Providing information is generally voluntary. We may be unable to answer an inquiry, arrange an event, or provide a requested feature without the information needed for it. Optional analytics or advertising consent is not required to use the public demo. We do not use this information to make solely automated decisions that produce legal or similarly significant effects on you.
3 Public demo and AI tools
The public demo uses simulated business data. Use fictional, nonconfidential prompts and do not enter personal data, customer production data, passwords, or other secrets. If you nevertheless submit personal data, this policy applies to our handling of it; the demo does not create a processor relationship or DPA with your organization.
Demo AI responses are generated using Amazon Bedrock. Your prompt and relevant conversation context are sent to that service to generate a response. Sellforte may retain conversation records and allow authorized personnel to review them for troubleshooting, security, and proportionate product improvement. Retention is explained below. AI responses can be incorrect; see the AI Use Statement and Demo Terms of Use.
For our own business activities, we may also use AI-assisted writing, analysis, and note-taking tools to help with correspondence, business records, and meeting notes. These providers may process information outside the EU/EEA under the safeguards below. We limit access and the information provided to the purposes described in this policy.
4 Who receives information
Authorized personnel and relevant group companies may access information for the purposes above. We use service providers for hosting and content delivery; security; website and demo operation; AI processing; communications, meetings, and note-taking; customer relationship management and marketing; events and surveys; analytics and advertising; and accounting, payments, and legal advice.
Providers processing data for us must follow our instructions and contractual data protection requirements. Some recipients, such as advertising platforms, professional advisers, and authorities, may act as independent controllers for their own legally permitted purposes. They are not all subprocessors under a customer's DPA.
We may disclose information where legally required, to protect or enforce legal rights, or in connection with a merger, financing, restructuring, or transfer of business, with appropriate confidentiality and data protection safeguards. Website analytics and advertising providers and technologies are described in the cookie section below.
5 International processing
Information may be processed in the EU/EEA and in other countries, including the United States, by group companies and service providers. This may include hosting, remote access, support, communications, AI and note-taking, analytics, and advertising. The recipients and locations for our own processing can differ from those agreed for a customer's production service.
Where GDPR transfer rules apply, we use an applicable adequacy decision or appropriate safeguards, such as the European Commission's Standard Contractual Clauses, together with additional measures where needed. An adequacy decision is used only where it covers the recipient and transfer. You may contact privacy@sellforte.com for information about the safeguards or a copy, subject to protection of confidential information.
6 Retention
- Demo conversations and identifiable usage, troubleshooting, and security records: up to 18 months from the interaction or event, with earlier deletion or anonymization when no longer needed. Relevant extracts may be kept longer for a documented incident, legal obligation, or legal claim, restricted to that purpose until it is resolved or the applicable retention requirement ends.
- Business contacts, inquiries, and relationship records: while the relevant inquiry, sales discussion, or business relationship is active and the information remains relevant to your role. When it ends or your role changes, we remove obsolete contact information; records still required for outstanding obligations, disputes, or statutory recordkeeping are retained separately for those purposes.
- Marketing subscriptions: until you unsubscribe or the subscription is closed. We retain the minimum information needed to honor your objection or withdrawal for as long as needed to prevent renewed unwanted contact.
- Event administration, recordings, transcripts, and survey responses: until the announced event, follow-up, or review purpose is completed. Any material retained as an ongoing business record follows the relationship-record criteria above; unnecessary recordings and identifiable detail are deleted or anonymized.
- Accounting and legal records: for the period required by applicable law or necessary for a specific legal claim, determined by the relevant statutory retention or limitation period and any pending proceedings.
- Cookies and browser storage: for their stated lifetimes, unless removed earlier. Server-side records are governed by the relevant purpose and retention criteria above. Statistics that no longer identify a person may be retained for historical reporting.
We limit retained information to what is needed for the applicable purpose. Deletion and anonymization also form part of our service-provider and backup handling; retained copies remain protected and are not reused for unrelated purposes.
7 Security
We use technical and organizational measures appropriate to the information and risk, including access restrictions, authentication, encryption where appropriate, monitoring, and contractual controls over service providers. No website or communication method is completely secure. Please do not send passwords or unnecessary sensitive information through public forms or the demo.
8 Your choices and rights
Contact privacy@sellforte.com to request access, correction, deletion, restriction, or, where applicable, a portable copy of your personal data. You may object to processing based on legitimate interests for reasons relating to your situation. You may object to direct marketing, including related profiling, at any time. You may also unsubscribe using the link in a marketing message.
Where processing relies on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing. Change optional tracking choices through Cookie Settings or the corresponding privacy controls on the site. These rights are subject to their legal conditions; we may need proportionate information to verify a request.
You may complain to the Finnish Data Protection Ombudsman or another competent supervisory authority, including in the EU/EEA country where you live or work.
9 Cookies and similar technologies
Our sites use cookies, local or session storage, pixels, and similar technologies to operate the sites, remember choices, measure use and advertising, and provide optional features. A technology can involve personal data or device access even if it does not use cookies.
Necessary technologies support requested functions and security. Optional analytics, advertising, and functionality technologies require consent where applicable. You can accept or reject optional categories and later change your choice through Cookie Settings or the site's equivalent controls. Browser settings can also restrict or delete stored information; doing so may affect site features. Accepting the Demo Terms does not itself provide consent to optional tracking.
Technologies used across our sites include HubSpot for site operation, forms, chat, and analytics; Google Analytics and advertising tools; Microsoft advertising and analytics tools; Clay for business-visitor intelligence; OpenAI advertising measurement; Plausible analytics; and Sellforte's own website measurement technology. Embedded content, such as videos, may use its provider's technologies. Availability depends on the page, feature, consent choice, and browser settings. Advertising and visitor-intelligence providers may combine interaction information with information they lawfully hold to measure campaigns or identify interested businesses.
The tables below describe cookies and browser storage used by site features. Availability depends on the page, feature, consent choice, and browser settings. Lifetimes run from setting or renewal and may be shortened by browser controls. Session storage normally ends when its browser tab is closed; local storage has no browser-enforced expiry and remains until removed, unless the application applies an expiry. Cookie and storage lifetimes are distinct from server-side retention.
Security and consent cookies used by an optional third-party feature do not make that feature necessary for using our website. Embedded videos may involve functionality, measurement, and advertising under the provider's settings and your choices. If you are signed in to a third-party service, it may also receive its existing account cookies when that service is loaded. These are governed by that provider's policies. Plausible visitor analytics does not use cookies or persistent browser storage.
Necessary functions and consent preferences
Cookies
| Cookie Name | Provider / Domain Title | Expiration | Purpose |
|
|
Cloudflare — .sellforte.com and supporting service domains, including .hubspot.com, .hsappstatic.net, .hsforms.com, .hs-sites-eu1.com, .hs-scripts.com, and .linkedin.com | 30 minutes of inactivity |
Used to distinguish between humans and bots; protects forms/assets with rate-limiting. |
|
|
Cloudflare — .sellforte.com |
Session |
Per-request rate limiting and security; validates legitimate traffic. |
|
|
HubSpot / Sellforte — .sellforte.com | 6 months on the website; up to 12 months when saved by the demo |
Stores the visitor’s cookie consent preferences so the choice persists. |
|
|
Sellforte — demo.sellforte.com | 6 hours |
Maintains user authentication and session continuity within the Sellforte demo environment. Required for secure API access and demo functionality. |
| __oaiq_consent | OpenAI / Sellforte — .sellforte.com | 30 days | Stores the consent choice for OpenAI advertising measurement. |
Storage declaration
| Storage Name | Provider | Storage and duration | Purpose |
| oaiq_consent | OpenAI / Sellforte | Local storage; until replaced or cleared | Remembers the advertising-measurement consent choice. Local storage has no browser-enforced expiry. |
Analytics
Cookies
| Cookie Name | Provider / Domain Title | Expiration | Purpose |
|
|
HubSpot, Inc. — |
30 minutes |
Tracks sessions to determine if HubSpot should increment session count and timestamps. |
|
|
HubSpot, Inc. — |
Session |
Detects if the visitor restarted the browser during a session. |
|
|
HubSpot, Inc. — |
6 months |
Main HubSpot analytics cookie; sets a unique visitor ID and timestamps. |
|
|
HubSpot, Inc. — |
6 months |
Visitor ID used for analytics and to deduplicate form submissions. |
|
|
Google LLC — |
Approximately 400 days in the current browser configuration |
Used by Google Analytics to distinguish users. |
|
|
Google LLC — |
Approximately 400 days in the current browser configuration |
Used by Google Analytics to persist session state. |
|
|
Microsoft Corporation (UET/Clarity) — |
1 year | Stores a Clarity measurement identifier and preferences for this site. |
|
|
Microsoft Corporation (UET/Clarity) — |
1 day | Connects page views into a Clarity session recording. |
| __sftr_cid | Sellforte — .sellforte.com | 365 days | Recognizes a browser for website measurement and attribution after analytics consent. |
Storage declaration
| Storage Name | Provider | Storage and duration | Purpose |
|
|
Microsoft Corporation (Clarity) |
Session storage |
Clarity session token used to group multiple user actions into one analytics session. |
| __sftr_aid | Sellforte | Local storage; no automatic time-based expiry | Stores a pseudonymous browser identifier for website measurement. It remains until removed by the site or cleared through browser controls. |
| __sftr_sid; __sftr_init | Sellforte | Session storage | Stores a tracking-session identifier and records whether session initialization has occurred. |
Advertising
Cookies
| Cookie Name | Provider / Domain Title | Expiration | Purpose |
|
|
Google LLC — |
90 days |
Stores ad click information to measure campaign effectiveness (Google Ads). |
|
|
Microsoft Corporation — |
Approximately 390 days |
Persistent ID for Microsoft Advertising attribution and frequency capping. |
|
|
Google LLC (DoubleClick) — |
13 months in the EEA, UK, and Switzerland; up to 24 months elsewhere |
Used for ad delivery and reporting (Google Marketing Platform). |
|
|
Microsoft Corporation — |
Approximately 390 days |
Unique user ID used by Microsoft sites/ads for measurement. |
|
|
LinkedIn Corporation — |
1 year | LinkedIn browser identifier used for diagnostics. |
|
|
LinkedIn Corporation — |
6 months |
Stores LinkedIn consent state used by LinkedIn insight/ads features. |
|
|
LinkedIn Corporation — |
1 day |
Supports LinkedIn data-center routing. |
|
|
Google LLC — |
1 year 1 month |
Supports Google services and ads security/preferences when ad tech is enabled. |
|
|
Google LLC — |
6 months |
Helps enforce security and fraud prevention for Google services used with ads. |
|
|
Google LLC — |
1 year 1 month |
Stores Google consent settings supporting ads-related services. |
|
|
Microsoft Corporation (UET) — |
1 day |
Identifies a session for Microsoft Advertising conversion measurement. |
| __obref | OpenAI / Sellforte — .sellforte.com | 365 days | Supports advertising measurement and attribution. |
Storage declaration
| Storage Name | Provider | Storage and duration | Purpose |
|
|
Google LLC |
Local storage; component-specific expiry, including short-lived state and up to 90-day records |
Google Ads click identifier used to measure conversions. |
|
|
Microsoft Corporation |
Local storage; approximately 390-day identifier lifetime |
Persistent visitor ID for Microsoft UET to measure conversions and returning visitors. |
|
|
Microsoft Corporation |
Local storage; approximately 390-day identifier lifetime |
Expiration timestamp for |
|
|
Clay (Clay.com) |
Session storage |
Stores an identifier for business-visitor intelligence and measurement within the browser session. |
|
|
Clay (Clay.com) |
Session storage |
Session data collected by Clay to analyse engagement and activity. |
|
|
Microsoft Corporation |
Local storage; 1-day identifier lifetime | Stores the Microsoft Advertising session identifier or its expiry time. |
|
|
Microsoft Corporation |
Local storage; 1-day identifier lifetime | Stores the Microsoft Advertising session identifier or its expiry time. |
| radar_sn_* | Clay | Session storage; cached values are treated as stale after 24 hours | Caches device-signal hashes used by visitor-intelligence technology. |
| oaiq_cs:* | OpenAI | Session storage | Stores state for advertising measurement during the browser session. |
Chat and embedded content
Cookies
| Cookie Name | Provider / Domain Title | Expiration | Purpose |
|
|
Google LLC (YouTube) — |
Session |
Supports the security and operation of an embedded YouTube video session. |
|
|
Google LLC (YouTube) — |
6 months | Supports YouTube preferences, service diagnostics, and measurement; may also support personalization or advertising depending on your choices. |
|
|
Google LLC (YouTube) — |
6 months |
Stores privacy preferences for YouTube embeds (e.g., consent mode state). |
|
|
Google LLC (YouTube) — |
6 months | Supports YouTube feature rollouts and measures their effects. |
| messagesUtk | HubSpot — .sellforte.com | 6 months | Recognizes chat visitors and supports continuity of chat conversations. |
| __Secure-YNID | Google / YouTube — .youtube.com | 6 months | Supports YouTube preferences, diagnostics, and measurement; may also support advertising depending on your choices. |
Storage declaration
| Storage Name | Provider | Storage and duration | Purpose |
| yt-icons-last-purged; yt-player-caption-persistence; ytidb::LAST_RESULT_ENTRY_KEY | YouTube | Local storage; retained or refreshed according to the player settings, or until cleared | Stores player maintenance information, caption preferences, and capability-check results for embedded videos. |
10 Updates to this policy
We publish updates here with a revised date and give additional notice of significant changes where appropriate. Where a new purpose requires consent, a policy update does not replace that consent.