Sellforte US Online Service Privacy Notice
Terms and Notices — Sellforte, Inc. — 2026-10-01
US. The contracting entity in the Order Form determines the applicable terms. For EU/rest of the world (excluding the US), see Sellforte Solutions Oy terms.
Sellforte US Online Service Privacy Notice
Version 2026-10-01
This notice explains personal information used in customer workspaces contracted with Sellforte, Inc. It distinguishes processing for your organization from separate Sellforte business and platform purposes. Your organization's executed agreement governs its Services; this notice does not replace that agreement or make newer terms apply automatically. This notice does not cover Sellforte's public website, recruiting, or employment activities.
Responsible entities and purposes
Your organization determines why personal information is processed in its workspace and is usually the controller or business, or acts for another controller. Sellforte, Inc. processes that information on its behalf under the applicable DPA. Sellforte's Affiliates Sellforte Solutions Oy (Finland), Sellforte Solutions GmbH (Germany), and Sellforte Solutions UK LTD (United Kingdom) and authorized suppliers assist with delivery. Contact your organization's administrator or privacy contact about its instructions and data.
Sellforte, Inc., a Delaware corporation, 2201 Spinks Road, Suite 252, Flower Mound, TX 75022, United States, is responsible for its separate customer relationship, contract administration, billing, business communications, platform security, and limited product-usage purposes. Sellforte Solutions Oy, business ID 2832424-2, Otakaari 5, 02150 Espoo, Finland, operates the platform on behalf of Sellforte, Inc. Contact privacy@sellforte.com.
Information processed for your organization
We process the permitted information supplied by you, your organization, its authorized sources, or your service use. Depending on configuration, it includes business contact and account details, roles and permissions, authentication identifiers, IP addresses, device and browser details, sessions and feature events, and personal information in authorized source data, reports, prompts, outputs, action records, and support requests. Recordings and transcripts are processed only when enabled with required notice and permission. Necessary account and access information is required to provide secure workspace access. Your organization chooses other content within the agreed service scope.
We use this information to authenticate users, provide the agreed marketing measurement and analytics, execute authorized actions, operate and secure the workspace, support users, and follow return or deletion instructions. It is subject to the DPA and is not available for unrelated Sellforte marketing, cross-customer profiling, or general-purpose or generative AI model training. Sensitive Data and known under-18 personal information are excluded from the standard service unless specifically agreed with appropriate safeguards.
Separate business and platform processing
Inc. uses business contact, contract, billing, and correspondence records to administer the customer relationship, provide required communications, comply with its legal duties, and establish or defend claims. Inc., with Oy acting on its behalf, may use limited account, technical, and security records to protect the platform, investigate abuse, and produce limited service-usage statistics. Historical business and investor metrics are anonymous totals rather than individual histories. Optional detailed product analytics requires the notice and consent applicable to the deployment. Troubleshooting content remains under the DPA rather than becoming unrestricted Feedback.
Recipients and locations
Authorized group personnel and delivery suppliers receive information only for their permitted functions and under appropriate confidentiality, processing, and security arrangements. Primary service hosting is in the agreed region, which is the United States by default. Support and development access from the EU and the UK and other supplier processing may occur as described in the DPA and its supplier schedule. Independently chosen external tools follow the organization's separate provider arrangements; connecting one can transmit selected information to that provider.
Separate business and platform records may be disclosed to the providers needed for the specified purpose, professional advisers, competent authorities where legally required, and parties to a lawful business transaction with appropriate safeguards. A US hosting region does not mean all processing is confined to the United States. Where the law requires safeguards for international transfers, we use them. Ask privacy@sellforte.com for the relevant recipients, countries, and safeguards.
Retention
Information processed for your organization follows its DPA and lawful instructions, including return, deletion, and the applicable retrieval and backup periods. Shorter legal and source-provider deadlines cover the copies within their scope.
Separate identifiable usage and security logs are retained for up to 18 months from each event, with earlier deletion or anonymization when no longer needed. Contract renewal does not restart that period. Identifiable Feedback and related correspondence may remain during the customer agreement and for up to 12 months afterward, with annual review and earlier removal of identity when follow-up no longer requires it. Anonymous statistics may remain only after effective deidentification. Sellforte maintains and uses deidentified information only in deidentified form and does not attempt to reidentify it, except to test whether its deidentification processes work.
Inc. retains separate contract, accounting, and billing records for the period required by applicable law and any documented lawful need to administer or defend the relationship. A specific incident, dispute, or legal hold may extend retention of necessary separate controller records, and the records are deleted or anonymized when it ends.
Choices and individual rights
Necessary authentication and session technologies enable secure access. Optional device access and analytics require the choices applicable to the deployment. We will honor legally required consent, withdrawal, and recognized opt-out signals. We do not sell or share Customer Personal Data or use it for cross-context behavioral advertising under the standard service. These commitments do not describe advertising technologies on Sellforte's public website, which are covered by separate disclosures.
Depending on applicable law and the responsible entity's role, you may request access, correction, deletion, portability, restriction, or opt-outs, and may appeal a denial where the law provides that right. We will not unlawfully discriminate for exercising protected rights. We may verify identity proportionately and accept authorized-agent requests where required. Contact privacy@sellforte.com; we will respond within applicable deadlines, and explain any permitted extension or denial. Requests about your organization's data are forwarded to it unless we must respond directly.
We do not use the information covered by this notice to make consequential individual eligibility decisions.
Changes
We may update factual and explanatory information through a dated notice and will provide notice and obtain consent for material processing changes where required. A revised notice does not itself authorize a new processing purpose or amend the customer agreement.
