Legal
Privacy Policy
Last updated 6 October 2026
This policy describes how Seasely handles personal data, in plain language. It applies to the website, the application and support.
What Seasely is
Seasely is a business-to-business outbound sales platform. A workspace describes what a company sells and whom it wants to reach; Seasely then finds matching businesses from public sources, qualifies them, verifies a business e-mail address, writes a short personalised e-mail and sends it from the customer's own connected mailbox, handles the replies and reports the results.
This policy explains what personal data Seasely processes, why, with whom it is shared and what rights you have. It covers the Seasely website, the application and support. Questions go to support@seasely.com.
In most of the processing below Seasely acts for its customers: the customer decides whom to contact and what to offer, Seasely provides the tooling. For account, billing and website data Seasely decides the purposes itself.
Account data
When you create an account we store your e-mail address, a display name, a salted password hash (never the password) when you sign up with a password, your e-mail verification state, the workspaces you belong to and your role in each, and security records such as sign-in attempts, session tokens (stored only as hashes), the time of your last sign-in and a hashed form of the IP address and browser identifier of each session.
Purpose: to let you sign in, keep your account secure, tell you about your account and apply your role inside a workspace. Legal basis: performance of the contract with you and our legitimate interest in keeping the service secure.
Signing in with Google
You can sign in with a Google account. Seasely then requests only your basic identity (OpenID Connect: your e-mail address, the fact that it is verified, your name and Google account identifier) and uses it to create or link your Seasely account. Signing in with Google gives Seasely no access to your mailbox, calendar, contacts or any other Google data.
Workspace and business configuration
A workspace holds the configuration you provide about your own business: your offer, the audience you want to reach, markets and locations, requirements and exclusions, the e-mail sequence you reviewed, your website address and the text you typed to describe your business. Seasely may use an AI model to turn that description into a structured draft that you then review and confirm.
Purpose: to run outreach the way you configured it. Legal basis: performance of the contract.
Prospect and lead data processed through the product
To find businesses that match a workspace, Seasely collects publicly available business information from the sources listed under Service providers: company name, website, business category, location and address, phone number, public ratings and review counts, and information published on the business's own website such as a general contact e-mail address and the services it offers. Seasely verifies whether a business e-mail address is deliverable, scores how well the business fits the workspace and records the outcome of every contact (sent, replied, bounced, unsubscribed).
This data is processed on behalf of and under the instructions of the customer who owns the workspace. Seasely does not sell prospect data, does not build profiles across customers and does not use one customer's prospects for another customer. Each workspace's data is isolated.
If you received an e-mail sent through Seasely and want to stop receiving them, use the unsubscribe link in the e-mail: the address is placed on that customer's suppression list and is not contacted by that workspace again. You can also write to support@seasely.com and we will help you reach the right customer or remove the record on their behalf where we are able to.
E-mail and outreach data
Seasely generates the e-mails a workspace sends, stores a copy of each sent message with its delivery state and provider message identifiers, and stores the replies that arrive in the connected mailbox for the conversations Seasely started (matched by message identifiers and thread identifiers). Replies are classified so the customer sees what needs attention; a reply may be classified by deterministic rules, by an AI model or by the customer. The customer can read, answer, snooze and close conversations in Seasely.
Seasely does not read, store or process mail in the connected mailbox that is unrelated to the outreach Seasely sent: it looks only for replies to its own messages and for bounce and unsubscribe notices about them.
Connecting a Gmail or Microsoft 365 mailbox
To send e-mails from your own address you connect a mailbox with OAuth. This is separate from signing in: a connected mailbox belongs to a workspace and is used for sending and reading replies, never for identity.
- Google: Seasely requests the Gmail permissions to send e-mail as you (gmail.send) and to read mail (gmail.readonly). Sending is used for the outreach you configured and for your manual replies in Seasely; reading is used only to find replies, bounces and unsubscribe notices to the messages Seasely sent and to keep the conversation threads correct.
- Microsoft 365 / Outlook: Seasely requests Mail.Send and Mail.Read (plus offline_access so the connection keeps working) for the same purposes.
- You can also connect an ordinary mailbox with SMTP and IMAP credentials, which Seasely uses for the same purposes.
OAuth tokens and mailbox credentials are encrypted at rest with a key that is not stored in the database, are never shown in the interface or written to logs, and are used only to perform the functions you authorised. You can disconnect a mailbox in Seasely at any time; you can also revoke Seasely's access in your Google or Microsoft account settings. Once access is revoked Seasely can no longer send or read anything from that mailbox.
Seasely's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide and improve the user-facing features described here, is not used for advertising, is not sold, and is not transferred to third parties except as needed to provide those features (for example to the hosting provider), to comply with law or as part of a merger or acquisition with notice to you. Humans at Seasely do not read your Gmail data except with your explicit permission for a support request, where required for security or legal reasons, or on aggregated, anonymised data for internal operations.
Authentication and security data
Seasely keeps hashed session tokens, hashed one-time tokens for e-mail verification, password reset and invitations, CSRF tokens, failed sign-in counters and temporary account locks, and an audit log of security-relevant events (sign-ins, password changes, invitations, role changes). Purpose: account security and the ability to investigate abuse. Legal basis: legitimate interest and our legal obligations to keep the service secure.
Billing and subscription data
Payments are handled by Stripe. Seasely stores your Stripe customer identifier, your plan, subscription status, billing period dates and how much of your plan allowance you have used. Seasely never receives or stores card numbers; Stripe collects them directly on its own pages. Purpose: to provide the plan you pay for and to issue invoices. Legal basis: performance of the contract and legal (accounting) obligations.
Usage, analytics and cost data
Seasely records what the product did for your workspace: companies found, leads qualified, e-mails sent, replies, positive replies, deals and the cost of the provider and AI calls made on your behalf. This is shown to you on your dashboard and used to allocate your plan allowance and to tune your own workspace's outreach. Seasely does not use third-party website analytics or advertising trackers.
Logs and diagnostics
Application logs record technical events with identifiers (request id, workspace id, user id, job id), the time and a short message. Secrets, tokens and e-mail bodies are masked or excluded before a line is written. When error monitoring is enabled, unhandled errors are reported to Sentry with the same identifiers and a stack trace, with cookies, headers, request bodies and token-like values removed. Purpose: to keep the service reliable. Retention: logs and error reports are kept for a limited period and then deleted.
Cookies and session data
Seasely uses only strictly necessary cookies: a session cookie that keeps you signed in, a CSRF cookie that protects forms against cross-site requests, short-lived cookies during a Google sign-in or an invitation, and small preference cookies for the interface. There are no advertising or third-party analytics cookies, so no consent banner is shown. See the Cookie notice for the full list.
Transactional e-mail
Seasely sends you account e-mails: e-mail verification, password reset, workspace invitations and replies to your support requests. These are delivered through Resend (or an SMTP relay configured by the operator). They contain one-time links that expire; the e-mail content is not used for marketing.
Purposes and legal bases in short
- Providing the service you signed up for, including running the outreach you configured (contract).
- Keeping accounts, mailboxes and data secure and preventing abuse (legitimate interest, legal obligation).
- Billing and accounting (contract, legal obligation).
- Improving the reliability and quality of the service using the data of your own workspace (legitimate interest).
- Answering your questions (contract, legitimate interest).
Service providers and subprocessors
Seasely runs on infrastructure and services operated by other companies, each bound by its own data processing terms. The current list, with the purpose and the categories of data each one receives, is published on the Subprocessors page and is kept up to date when a provider changes.
Data retention
- Account data: for as long as your account exists, then deleted or anonymised within a reasonable period after deletion.
- Workspace, prospect and outreach data: for as long as the workspace exists and you need it to run and understand your outreach; suppression (unsubscribe and bounce) records are kept so a contact is not written to again.
- Session and one-time tokens: until they expire or are used (sessions after 7 days of inactivity or 30 days at most; reset links after 1 hour; verification links after 48 hours; invitations after 7 days).
- Billing records: for the period required by accounting law.
- Logs and error reports: for a limited rolling period.
Deletion
You can disconnect mailboxes, remove team members and revoke invitations yourself. To delete your account or a whole workspace, write to support@seasely.com from the e-mail address of the account. Deleting a workspace removes its configuration, prospects, messages and conversations; a short-lived backup copy may persist until the backup rotates out. Data we must keep by law (invoices) is retained for the legal period only.
Security
Seasely uses HTTPS everywhere, encrypts mailbox credentials and OAuth tokens at rest, stores passwords and tokens only as hashes, isolates every workspace's data from every other workspace, limits who can see what through roles, protects forms against cross-site requests, rate-limits sign-in and other sensitive actions, and keeps an audit trail of security events. No method of transmission or storage is perfectly secure; if you believe your account was compromised, contact support@seasely.com immediately.
Where data is processed
Seasely is operated from Hungary. The service is hosted on cloud infrastructure and uses service providers that may process data in the European Union and in other countries, including the United States. Where personal data leaves the European Economic Area, Seasely relies on the provider's standard contractual clauses or an equivalent recognised mechanism. The Subprocessors page states the known region of each provider.
Your rights
Depending on where you live you may have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to its processing, to receive it in a portable form and to withdraw consent where processing is based on consent. To exercise a right, write to support@seasely.com; we may ask you to verify your identity. You also have the right to lodge a complaint with your data protection authority. In Hungary this is the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH).
If your data was processed because a Seasely customer chose to contact you, we will forward your request to that customer and help them answer it.
Contact
Seasely, Hungary. Privacy questions and requests: support@seasely.com.
Changes to this policy
We may update this policy as the service evolves. The date at the top shows the current version; material changes are announced in the application or by e-mail before they take effect.