Privacy Policy

中文

Effective date: 【TBD: publication date】

1. Who this policy applies to

This policy explains how 【TBD: full legal entity name】 ("we", "us") handles three categories of personal information: (1) Seat Users — employees authorised by a customer organisation to use the platform; (2) personal information within customer business data — data imported or generated by a customer in the course of using the services; (3) business contact information — business contact details of target companies and their employees, obtained by the platform from public sources and third-party data providers. For categories (2) and (3), we process the information on the customer's instructions, and the customer is the party that decides on the processing; where data subjects exercise their rights, we will assist the customer in responding, or respond directly where we have agreed to do so.

2. What we collect and process

Seat account information: name, work email address, and password (stored only as an encrypted hash). Usage and log data: sign-in records, activity logs and request identifiers, used for security auditing and troubleshooting. Product analytics data: feature usage behaviour, processed through a product analytics tool. Customer input: ideal-customer-profile descriptions, imported lists, and research questions. Business contact information: company name and registration details, contact name, job title, work email address, and links to public professional profiles such as LinkedIn — we process contact information in a business context only, and every record carries its source, the basis on which it was obtained, and its retention period. Outreach data: the content and delivery status of emails sent following customer approval. Channel credentials: mailbox credentials linked by the customer are stored under envelope encryption and are decrypted only at the moment a sending or receiving task executes; they are never echoed back in any log, error message or interface.

3. Purposes and bases for processing

We process seat account information and business data in order to perform our service contract with the customer, and we process log data as reasonably necessary to maintain the security of the platform. Business contact information is processed for the sole purpose of supporting business-to-business development: for contact information imported by a customer, the lawfulness of the processing is confirmed by, and is the responsibility of, that customer (the source is labelled accordingly as imported); for business contact information obtained through the platform, the basis for the lawfulness of the processing is determined by the customer as the party deciding on the processing, and we process it on the basis of legitimate interests to the extent of our own obligations 【Pending counsel: this section to be revised once the characterisation of the parties' roles and the lawfulness baseline for each target market (L-7 / L-10) are settled】. All of the above processing is accompanied by the safeguards and the always-available opt-out described in Section 6 of this policy.

4. Storage location and cross-border transfers

Our application and primary database are deployed in Singapore; some providers are located in the United States or the European Union (see the subprocessors page for the full list and locations). If you are a Seat User located in mainland China, your account information and usage logs will be stored on servers outside mainland China (in Singapore); we handle the related cross-border matters in accordance with the requirements of applicable law 【Pending counsel: wording to be added once the transfer route is settled】. Outreach email is sent through email infrastructure located in the United States, and email content and recipient information will be processed in the United States.

5. Retention periods

Raw web page snapshots are retained for 30 days by default (configurable by the customer between 7 and 90 days), after which only the structured summary and the source citations are retained. Application logs and model invocation records are retained for 90 days. The billing ledger is retained permanently to meet statutory and audit requirements; where a deletion request is made, the identifying information referenced in the ledger is de-identified. Residual copies of deleted data in backups persist for no more than 35 days.

6. Your rights

You have the right to access, correct and delete your personal information, and to obtain a copy of it. Seat Users can view and update their own information in account settings; business contacts can make a request using the contact details at the foot of this page. Deletion requests are completed within 30 days, and we will confirm the outcome to you in writing once complete. Every outreach email you receive contains an unsubscribe link, and unsubscribing takes effect immediately and permanently — we operate a global suppression mechanism to ensure you are not contacted again after you unsubscribe. If you object to processing carried out on the basis of legitimate interests, we will stop the relevant processing; the unsubscribe mechanism is also a direct channel for exercising that right to object.

7. Provenance and traceability

Every business contact record in the platform carries source references, the basis on which it was obtained, and its retention period. Inferred fields that are not supported by direct evidence are explicitly labelled as inferred and are not presented as fact. Contact data is isolated between customers, and we do not reuse contact data obtained for one customer for the benefit of another.

8. Security measures

We operate layered security controls: row-level tenant isolation in the database (a two-layer defence in which unauthorised queries return empty by default), envelope encryption of channel credentials (a separate key per credential), least-privilege access, comprehensive audit logging, and secret-leak and privacy-field scanning gates in continuous integration.

9. Cookies and analytics

We use strictly necessary cookies to maintain your signed-in session, and a product analytics tool to improve the product experience 【TBD: cookie consent mechanism, to be added once configured for the requirements of the target market】.

10. Changes and contacting us

When this policy is updated we will publish the revision on this page with its effective date, and we will separately notify customers of material changes. For privacy-related requests, please contact: 【TBD: privacy contact email address】.

This page is derived from our internal compliance memorandum; the version mapping is kept in our release records.