Privacy Policy

Publication date: 04.04.2026

This Privacy Policy explains how smartNsales AG, operating under the name Sealio, collects and processes personal data when you visit our website, communicate with us, or use the Sealio service.

Contact: privacy@mysealio.com

1. Who we are

smartNsales AG is a Swiss company registered under number CH-150.4.478.089-1, with UID/VAT number CHE-422.097.458 MWST and registered office at Habsburgerstrasse 32, 6003 Luzern, Switzerland.

For personal data that we determine the purposes and means of processing, smartNsales AG is the controller. You can contact our privacy team at privacy@mysealio.com.

2. Scope and our role

This Privacy Policy applies to our website, sales and support communications, accounts, and the Sealio service.

When a customer uploads or otherwise provides personal data in documents, proposals, knowledge bases, or other Customer Content, the customer normally determines why that data is processed. In that context, the customer is the controller and we act as its processor or service provider. The applicable customer agreement and data processing agreement govern that processing.

This Privacy Policy does not apply to third-party websites or services that we do not control.

3. Personal data we collect

Business and contact data, such as your name, work email address, telephone number, employer, job title, professional profile information, correspondence, and meeting details.

Account and authentication data, such as your name, email address, organization, role, account identifiers, login events, and access permissions.

Product and usage data, such as features used, actions taken, workspace activity, preferences, feedback, and support requests.

Technical and security data, such as IP address, browser and device information, timestamps, diagnostic events, audit records, and security logs.

Customer Content, such as tender documents, questionnaires, proposals, templates, knowledge materials, comments, instructions, generated content, and related metadata.

Website and marketing data, such as pages visited, referring source, campaign interactions, form submissions, and communication preferences.

4. How we collect personal data

We collect personal data directly from you, from the organization you represent, through your use of our website and service, and from public or professional business sources.

For business-to-business outreach, we may use publicly available professional information and information supplied by business-data or communication service providers. We use this information only for relevant professional communications and relationship management.

5. Why we process personal data

We process personal data to provide and administer the service; create and secure accounts; analyze documents and generate requested outputs; provide support; communicate about contractual and service matters; manage sales relationships; maintain and protect our systems; comply with law; establish, exercise, or defend legal claims; and improve the service using aggregated or de-identified usage information.

Depending on the context, we rely on performance of a contract, steps requested before entering a contract, compliance with legal obligations, our legitimate interests or those of a third party, and consent where required. Our legitimate interests include operating and securing our business, supporting customers, preventing misuse, and conducting relevant business-to-business communications.

We do not sell personal data. We do not use Customer Content for advertising or to train AI models.

6. Customer Content and AI processing

We process Customer Content only to provide, secure, support, and maintain the service, or as otherwise instructed by the customer. Product improvement uses only aggregated or de-identified usage information unless the customer expressly agrees otherwise.

Sealio uses OpenAI Ireland Limited through an EU endpoint for production language-model inference. Only relevant excerpts, rather than complete documents, are sent when needed to perform a requested function. Provider retention may be up to 30 days for abuse monitoring. Customer Content is not used to train provider models.

AI-generated outputs may be incomplete or inaccurate. Users must review and approve outputs before relying on them or submitting them externally.

7. How we share personal data

We disclose personal data only where necessary to our authorized personnel, professional advisers, service providers, subprocessors, public authorities where legally required, and parties involved in a corporate transaction subject to appropriate confidentiality protections.

Our service providers support hosting, database and authentication, application infrastructure, AI processing, email delivery, monitoring, security, communications, and business operations. They may process data only for the contracted purpose and under appropriate confidentiality and data-protection obligations.

The current production subprocessor list, locations, and purposes are available in the Sealio Trust Center at https://trust.mysealio.com/.

8. Storage and international processing

Customer Content is primarily stored in Zurich, Switzerland. Certain authorized subprocessors process limited Customer Content and account data in Switzerland and the European Economic Area, as described in the Sealio Trust Center.

Where personal data is transferred to a country without an adequate level of protection, we use an available legal transfer mechanism and appropriate safeguards, such as recognized standard contractual clauses, unless an exception applies.

9. Retention

Customer Content and inactive account data are deleted within 30 days after termination, unless the applicable customer agreement states otherwise. Backups are deleted through normal rotation within 90 days.

Security and application logs are normally retained for 90 days, unless they are needed for an active security incident or investigation.

Sales-prospect data is retained for up to 24 months after the last meaningful interaction. Suppression and opt-out records are retained as necessary to respect communication preferences.

Contracts, invoices, and related records are retained for the period required by applicable law. We may retain information longer where necessary to comply with law, resolve a dispute, enforce an agreement, or investigate a security matter.

10. Security

We use technical and organizational measures designed to protect personal data, including access controls, encryption in transit and at rest where appropriate, restricted administrative access, monitoring, logging, backups, and incident-response procedures.

No system is completely secure. Users must protect their credentials and promptly report suspected unauthorized access to security@mysealio.com. Further information about our security practices is available in the Sealio Trust Center.

11. Your rights

Subject to applicable law, you may request access to, correction of, deletion of, restriction of, or portability of your personal data, and may object to certain processing. Where processing is based on consent, you may withdraw consent at any time without affecting earlier lawful processing.

You may also lodge a complaint with the competent data-protection authority. In Switzerland, this is the Federal Data Protection and Information Commissioner. If you are in the EEA or United Kingdom, you may contact your local supervisory authority.

To exercise a right, contact privacy@mysealio.com. We may need to verify your identity and authority before responding.

12. Business communications

We may send relevant service, product, or business communications to professional contacts where permitted by law. You can opt out of non-essential marketing communications at any time by using the unsubscribe mechanism or contacting privacy@mysealio.com.

We may still send necessary transactional, security, and contractual communications.

13. Cookies and similar technologies

We use cookies and similar technologies that are necessary to operate and secure the website. We use non-essential analytics or marketing technologies only where permitted by law and, where required, after obtaining consent.

You can manage available choices through our cookie controls and browser settings. More information is provided in our Cookie Policy.

14. Sensitive data and children

The service is intended for business users and not for children. We do not knowingly collect personal data from children.

Customers may include sensitive personal data, professional secrets, or regulated information in Customer Content only where they have a lawful basis, appropriate authority, and permission under the applicable customer agreement. Customers must not upload payment-card data, authentication secrets, or unlawful content.

15. Automated decision-making

Sealio provides AI-assisted analysis and drafting tools, but does not make decisions that produce legal or similarly significant effects about individuals on our own behalf. Customers remain responsible for how they use the service and its outputs.

16. Third-party services and links

Our website and service may link to or interoperate with third-party services. Those third parties process personal data under their own terms and privacy notices when they act independently from us.

17. Changes to this policy

We may update this Privacy Policy to reflect changes in law, our service, or our processing practices. We will publish the updated version and its publication date on this page. Where required, we will provide additional notice.

18. Contact

Privacy questions and rights requests: privacy@mysealio.com.

Security reports: security@mysealio.com.

Legal notices: legal@mysealio.com.

Loslegen

Bereit, mehr Ausschreibungen zu gewinnen?

Bringen Sie ein echtes RFP mit. Wir zeigen Ihnen, wie Sealio es in weniger als 10 Sek. analysiert.