Sellforte Online Service Privacy Notice

Terms and Notices — Sellforte Solutions Oy — 2026-09

EU/rest of the world (excluding the US). The contracting entity in the Order Form determines the applicable terms.


Sellforte Online Service Privacy Notice

Version 2026-09-11

This notice explains how personal data is used in Sellforte's customer Online Service. It separates processing for your organization from Sellforte's own purposes. Our public demo, website, marketing, billing, and broader business relationships follow our general privacy policy. Applicants and employees have separate notices.

1 Who is responsible

For your organization. Your organization, usually your employer, decides why and how personal data is used in its workspace. It is the controller, or acts for another controller. Sellforte processes Customer Personal Data on its behalf as a processor or subprocessor under the Data Processing Appendix (DPA). This includes account, access, service-use, and support data processed for the organization.

For our own purposes. Sellforte Solutions Oy is controller for the activities in Section 3. Our business ID is 2832424-2 and our address is Otakaari 5, 02150 Espoo, Finland. Contact privacy@sellforte.com. The same type of data, such as a login event, can serve different purposes; our role depends on the particular use.

2 Data processed for your organization

Account and access data: your name, work email, organization, role, authentication identifiers, and permissions, supplied by you or your organization.

Usage and technical data: IP address, device and browser information, sessions, timestamps, feature use, and access or audit logs generated through use.

Service content: personal data in uploaded or connected data, reports, prompts, AI Output, and action records, depending on the organization's configuration.

Support content: requests, correspondence, and attachments; recordings or transcripts only when enabled with the required information and permissions.

We use these data to authenticate users, operate and secure the workspace, provide the agreed features, and resolve support issues. Necessary account and access information is required to use the service. Your organization decides what other content is supplied.

Lawful basis. The responsible controller determines and explains its basis, which may be legitimate interests, a legal obligation, consent, or a contract with the individual, depending on the purpose. The service agreement between Sellforte and your organization is not itself a contract with you or your consent. Sellforte follows lawful instructions under the DPA rather than choosing a separate basis for its own reuse of these data.

3 Sellforte's own purposes and lawful bases

Security and abuse prevention. We use limited account, technical, and audit information to protect the platform and its users, investigate incidents, and establish or defend legal claims. Our basis is our legitimate interest in security and protecting legal rights.

Product-usage statistics. We use limited usage events, feature identifiers, timestamps, and account identifiers where needed to count distinct active users and understand adoption. Our basis is our legitimate interest in improving the service and measuring its use. Historical weekly and monthly active-user totals and feature-use trends used for business and investor reporting are anonymous, without individual-user histories. Consent applies to nonessential device storage or access where required.

Feedback and service communications. We use relevant business contact details, Feedback, and related correspondence to respond, follow up suggestions, improve the service, and communicate service or security information. Our basis is our legitimate interest in operating and improving the service and communicating with users. Customer content supplied for troubleshooting remains under the DPA; calling it Feedback does not change its status.

Legal duties and consent. We rely on a legal obligation where a law requires particular processing, such as handling GDPR rights requests or making required incident notifications. Where an optional activity requires consent, we explain the purpose when asking and allow withdrawal. We rely on legitimate interests only where the processing is necessary and your rights and interests do not override them.

This notice does not authorize independent reuse of Customer Personal Data or your organization's confidential content. Identifiable and pseudonymized information remains personal data. Other account-management correspondence and meeting notes follow our general privacy policy.

4 Recipients and international transfers

Processing for your organization. DPA Annex C lists the authorized subprocessors, their functions, and processing locations. Annex D describes transfer safeguards. Primary hosting is in the EU by default, or another agreed region; authorized support and supplier operations may occur elsewhere. Subprocessor changes follow the DPA's notice and authorization process.

Processing for Sellforte’s own purposes. We use the following service-provider groups for the purposes described in this notice. Providers acting as our processors work under processing agreements; their list may differ from DPA Annex C.

Infrastructure and security. Cloud hosting, storage, security, and technical monitoring providers receive the account identifiers, technical records, and logs needed to operate and protect these activities. EU hosting may still involve authorized support or other processing outside the EEA.

Communications and contact management. Microsoft 365 and HubSpot handle business contact details, service correspondence, Feedback, and communication preferences to support communications and follow-up. Their service and support operations may involve processing outside the EEA.

AI assistance. We may use AI tools to draft or analyze selected own-purpose correspondence or controller-level logs. These tools may process data outside the EU and EEA, including in the US; they do not necessarily follow the Customer’s service-hosting region.

Meeting notes. We may use note-taking tools for account-management notes and transcripts, including participant details and meeting content, for the separate business-relationship purposes described in our general privacy policy. Processing may occur outside the EU and EEA, including in the US.

Only data needed for the relevant purpose is shared. Customer Personal Data processed under the DPA is kept out of these separate AI and note-taking tools, including troubleshooting extracts and transcripts containing that data. The international-transfer safeguards below apply to our own processing.

Authorized Sellforte personnel and group companies in Finland, Germany, the UK, and the US may access data as needed for the relevant purpose. Providers engaged as our processors act under processing agreements and instructions. Tools your organization obtains independently follow that provider's own terms and privacy information.

International processing for our own purposes. These providers may process data outside the EEA, including in the US, through hosting, support, and other operations. The Customer's service-hosting region does not determine where our separate controller records are processed. We use an applicable adequacy decision or appropriate safeguards, such as EU Standard Contractual Clauses, with additional measures where required. Contact privacy@sellforte.com for recipient and country details or a copy of relevant safeguards.

We may also disclose necessary information to professional advisers for legal claims, authorities where legally required, or parties to a business transaction where lawful and subject to appropriate safeguards.

5 How long we keep data

Data processed for your organization. We follow its instructions and DPA Section 11.1, including for support records and logs. Under ToS Section 17.6, the usual retrieval period is 30 days after termination or completion of switching, whichever is later, followed by deletion from active systems. Backups expire no later than 12 months after that later event. Earlier lawful deletion instructions and shorter mandatory deadlines prevail; legally required retention is limited by the DPA. Retained copies stay protected and are used only for permitted purposes.

Our own usage and security logs: up to 18 months from each event, then deletion or anonymization. This supports seasonal usage analysis and investigation of delayed or long-running attacks. We minimize the data, restrict access by purpose, and assess the need for retention. Renewal of the customer agreement does not restart the clock.

Identifiable Feedback and related correspondence: during the customer agreement and for up to 12 months after it ends, to support follow-up and preserve relevant improvement context. We review the need for identity at least annually and remove it sooner when it is no longer needed.

Anonymous statistics: may remain after the underlying logs or accounts are deleted. Before treating statistics as anonymous, we assess whether individuals can reasonably be identified, including through small groups, repeated reports, or other available information.

Specific incidents, disputes, or legal duties: relevant controller records may be isolated for longer. We record the reason and expiry trigger, review the hold at least every six months, and delete or anonymize the records when the matter is finally resolved and applicable legal retention or limitation periods expire. These exceptions do not extend retention of Customer Personal Data under the DPA.

These limits apply to the relevant records held by our providers too. Other controller records follow the general privacy policy. We protect personal data through access controls, encryption, logging, personnel confidentiality, and proportionate security measures.

6 Cookies and similar technologies

Necessary authentication and session technologies enable secure access. Optional analytics technologies are used only with consent where required, with information about the technologies and available choices. You can refuse or withdraw that consent without losing core service functions.

7 Your rights and how to contact us

For your organization's processing: contact its privacy contact or administrator, normally through your employer. If it acts for another controller, it can identify the right contact. Sellforte assists with requests under the DPA. If you contact us directly, we promptly forward the request to the Customer and act on its instructions or as required by law.

For Sellforte's own processing: contact privacy@sellforte.com directly. You do not need to go through your employer. You can ask us which processing applies if you are unsure.

Depending on the circumstances, you may request access, correction, deletion, or restriction. You may object to processing based on legitimate interests for reasons relating to your situation, and withdraw consent without affecting earlier lawful processing. Portability applies to qualifying automated processing based on consent or a contract with you; it does not apply to every record.

We respond to requests for our controller processing within one month. If a permitted extension is needed, we explain why within that month. We may request proportionate identity verification. You may complain to the Finnish Data Protection Ombudsman or your competent local authority.

Visitors to customer websites or apps. That processing is explained in the operator’s visitor notice and our Tracking Technology Guidance, rather than this Online Service notice. Where joint controllership applies, visitors may exercise their rights against either the Customer or Sellforte.

Sellforte does not use the data covered by this notice to make solely automated decisions about individuals with legal or similarly significant effects.

We may update factual information and explanatory wording through a dated notice where law permits. We will communicate material processing changes when required, explain a new purpose before it starts, and obtain consent where required. Updating this notice does not itself create a lawful basis or change the Agreement.

Back to document navigation

Ready to see Sellforte in action?