Privacy Policy
Last updated: October 2, 2026
This Privacy Policy explains how Sellinger AI OOD ("Sellinger", "we", "us") handles personal data when you visit sellinger.ai, use the Sellinger platform at app.sellinger.ai and our related services (the "Service"), or are contacted through the Service. It is written to meet the EU General Data Protection Regulation ("GDPR"), the UK GDPR where it applies, the Bulgarian Personal Data Protection Act and US state privacy laws, including the California Consumer Privacy Act ("CCPA").
1. Who Is Responsible for Your Data
The controller of the personal data described in this policy is:
Sellinger AI OOD („Селинджър АИ“ ООД)
UIC (EIK) 208752836, registered in the Commercial Register and Register of Non-Profit Legal Entities kept by the Registry Agency of the Republic of Bulgaria
Registered office and address of management: Ring Tower business building No. 1, bl. 621, entr. 1, fl. 3, apt. 1, Mladost district, Sofia 1766, Bulgaria
Managed by Asen Asenov Levov and Viktorio Borisov Shopov, each acting separately
Email: hello@sellinger.ai · Phone: +359 896 699 009
For any privacy question or request, write to hello@sellinger.ai with "Privacy" in the subject line. We have not appointed a data protection officer; our managers are responsible for data protection. If we appoint one, we will publish their contact details here.
1.1 When we are a controller and when we are a processor
- We are the controller for data about our customers, their users, website visitors and people who contact us.
- We are a processor for the personal data our customers put into the Service or collect with it, such as their lead lists, the people their AI agents contact, conversation history, call recordings and website visitor signals. Our customers decide whom to contact and why. If you were contacted by a business using Sellinger, that business is responsible for your data, and you should read its privacy notice and direct requests to it. We will forward any request we receive to the right customer and help them answer it, and you can always object to us directly (Section 10).
2. Personal Data We Collect
2.1 Customers and their users
- Account data: name, business email, password (stored only as a hash), job title, company, phone, time zone, language and profile photo.
- Sign in data from Google, Microsoft or your single sign on provider: name, email address, profile photo and a unique ID. We do not receive your password.
- Billing data: billing name and address, VAT number, plan, invoices and payment status. Card details are collected and stored by Stripe; we only see the card brand, last four digits and expiry.
- Connected account data: identifiers and access tokens for the LinkedIn, email, WhatsApp, Instagram, Facebook, telephone, calendar and CRM accounts you connect, and the messages and contacts in them that the Service needs to work.
- Content: personas, prompts, knowledge base files, campaigns, notes and settings you create.
- Usage and device data: log in times, features used, IP address, browser, device and error logs.
- Support data: messages to our support team, chat with our in app assistant Mr Sellinger, and call recordings when you agree to be recorded.
2.2 Website visitors and prospects of Sellinger
- Form and booking data: name, email, company, phone and your message when you contact us or book a demo.
- Technical and cookie data: IP address, browser, pages viewed, referrer, campaign parameters (such as UTM tags and ad click IDs), and analytics and advertising identifiers, subject to your cookie choices (Section 12).
- Our own outreach: if we contact you about Sellinger, we use your business contact details, such as your name, job title, employer, business email and public professional profile.
2.3 Data we process for customers
As a processor we handle, on our customers' instructions: contact and professional profile data of their leads, message and email content, conversation history, call audio and transcripts, live chat messages, meeting details, enrichment results and website visit signals collected with the customer's tracking pixel. The customer's own privacy notice and our Data Processing Agreement govern this data.
You must provide account and billing data to conclude a contract with us; without it we cannot provide the Service. All other data you give us is optional.
We do not intend to process special categories of data (such as health or religious data) and our customers are not permitted to use the Service to target people based on them.
3. Why We Use Your Data and Our Legal Bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating your account, providing the Service, running your agents and connected accounts, customer support | Contract (Art. 6(1)(b)) |
| Billing, invoicing, accounting and tax records | Legal obligation (Art. 6(1)(c)) and contract |
| Security, fraud and abuse prevention, enforcing our Terms, protecting platform accounts | Legitimate interests (Art. 6(1)(f)): keeping the Service, our customers and Recipients safe |
| Improving the Service, fixing errors, product analytics on the platform | Legitimate interests: a reliable and useful product |
| Website analytics and advertising cookies | Consent (Art. 6(1)(a)); you can withdraw it at any time |
| Service and account emails (billing, security, important changes) | Contract and legitimate interests |
| Marketing emails to customers about similar services, with an opt out in every message | Legitimate interests, and consent where the law requires it |
| Business to business outreach about Sellinger | Legitimate interests: telling businesses about our services |
| Responding to legal requests, establishing or defending legal claims | Legal obligation and legitimate interests |
Where we rely on legitimate interests, we have balanced them against your rights, and you can object at any time (Section 10).
4. Your Conversations and Connected Accounts
- Your conversations, messages, lead lists, results and Connected Accounts belong to your Workspace. We access them only to run the Service for you (for example so your Agents can read replies and send messages), to give support you ask for, to review and improve your Agents' performance, to keep the Service secure, and to comply with the law.
- Your conversations and Connected Accounts can only be used by your own Sellinger account. No other customer can see, access or use them, and we never sell them.
- We do not use your conversations or any other customer data to train AI models.
5. AI Processing
- The Service uses large language models from the providers listed in Section 7 to write and answer messages, summarize conversations, research companies and analyze results. Only the data needed for each task is sent.
- We use these providers through business APIs under terms that do not allow them to use our data to train their models. We do not use customer data to train AI models.
- The Service does not make decisions about individuals that produce legal or similarly significant effects within the meaning of Article 22 GDPR. Lead scores and intent signals are sales aids for human teams.
- AI generated content can be wrong. If something an agent said about you is inaccurate, contact the business that sent it or us, and it will be corrected.
6. Connected Accounts and Platform Data
6.1 LinkedIn, email, WhatsApp and Instagram
These connections run through our provider Unipile. We do not store your platform passwords. Access is authorized through Unipile and is used only to send, receive and sync the messages, invitations and contacts your agents need. Disconnecting an account in the Service stops all further access.
6.2 Facebook and Instagram Pages (Meta)
If you connect a Facebook or Instagram Page through Meta, we store the Page conversations, comments, Page metadata and access tokens needed to manage messages for you. We use Meta Platform Data only to provide the features you enable, never sell it, and delete it on request; see our Data Deletion Instructions.
6.3 Google user data
If you sign in with Google, we receive only your basic profile (name, email address and photo). Sellinger's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this data, use it for advertising, or use it to train AI models.
6.4 AI assistant connectors
- When you connect an AI assistant such as Claude or ChatGPT through our Model Context Protocol connector, the assistant can access the Workspace data you allow at consent, including leads, conversations, campaigns, analytics and meetings, and acts on your behalf within that access.
- You choose full access, which lets the assistant read data and take actions such as sending messages or updating leads, or read only access.
- Access tokens expire after 8 hours and can be refreshed for up to 90 days without reconnecting. Access ends when you disconnect, are removed from the Workspace, or the token is revoked.
- Data the assistant reads is processed by its provider under that provider's own terms and privacy policy. We log connector requests for security auditing.
7. Who We Share Data With
We do not sell personal data. Website advertising cookies may count as sharing for cross context behavioral advertising under some US state laws (Section 12). We share data only with:
- Service providers (sub-processors) who process data for us under written contracts with confidentiality and security obligations. The current list is below. Customers are notified of new sub-processors as set out in our DPA.
- Platforms you connect, to deliver your messages and calls (for example LinkedIn, Meta or your email provider), and integrations you choose (for example HubSpot or Calendly).
- Your organization: Workspace admins and, for white label portals, the partner that operates the portal, can see data in the Workspace.
- Authorities and advisers, when required by law or needed to establish, exercise or defend legal claims, and our lawyers, accountants and auditors under confidentiality.
- A buyer or successor in a merger, acquisition, financing or sale of assets, bound by this policy.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. (on Amazon Web Services) | Database, authentication and file storage | EU (Stockholm, Sweden) |
| Google Cloud (Google Ireland Ltd.) | Application servers and background workers | EU (Finland) |
| Vercel Inc. | Web hosting, content delivery and performance analytics | Global edge network, USA |
| Stripe Payments Europe Ltd. | Payments, subscriptions and invoicing | EU, USA |
| Unipile SAS | Connection to LinkedIn, email, WhatsApp and Instagram accounts | EU (France) |
| Google (Gemini API) | AI language models for writing, analysis and research | USA, EU |
| Anthropic PBC | AI language models for writing and analysis | USA |
| OpenAI LLC | Text embeddings for knowledge base search, where enabled | USA |
| ElevenLabs Inc. | Voice synthesis and call handling for voice agents | USA, EU |
| Twilio Inc. | Telephone numbers, calls and SMS | USA, EU |
| Meta Platforms Ireland Ltd. | Facebook Page and Instagram messaging via the Graph API, when you connect them | EU, USA |
| Resend Inc. | Transactional and account email | USA |
| AgentMail Inc. | Managed mailboxes for email agents, where enabled | USA |
| AI Ark | Company and contact enrichment | USA |
| Lusha Systems Ltd. | Contact enrichment, where enabled by you | Israel, USA |
| Firecrawl and Serper | Public web page retrieval and web search for research | USA |
| PostHog Inc. | Product analytics | EU (Frankfurt, Germany) |
| Functional Software Inc. (Sentry) | Error monitoring | USA |
8. International Transfers
Our main database and servers are in the European Union. Some providers above process data outside the European Economic Area, mainly in the United States. We transfer data only where the destination has an adequacy decision (including certified companies under the EU US Data Privacy Framework), or under the European Commission's Standard Contractual Clauses (with the UK Addendum for UK data), together with additional safeguards where needed. You can ask us for a copy of the relevant safeguards.
9. How Long We Keep Data
| Data | Retention |
|---|---|
| Account and Workspace data | For the life of the account, then deleted or irreversibly anonymized within 90 days after closure |
| Customer Data we process as processor | As instructed by the customer; deleted or irreversibly anonymized after the post termination export period in our DPA |
| Invoices and accounting records | 10 years, as required by the Bulgarian Accountancy Act |
| Security, access and connector logs | Up to 12 months |
| Support conversations | Up to 3 years after the last contact |
| Website enquiries and demo requests that do not lead to a contract | Up to 2 years after the last contact |
| Marketing and analytics cookie data | As listed in Section 12 |
| Suppression list entries | For as long as needed to honor your objection |
Backups are overwritten on a rolling cycle. We may keep data longer where needed to establish or defend legal claims, or where the law requires it.
10. Your Rights
Under the GDPR you have the right to:
- access your personal data and receive a copy;
- have inaccurate data corrected;
- have your data erased;
- restrict processing;
- receive data you gave us in a portable format;
- object to processing based on legitimate interests, and to direct marketing at any time, including profiling for that purpose;
- withdraw consent at any time, without affecting earlier processing; and
- lodge a complaint with a supervisory authority. In Bulgaria this is the Commission for Personal Data Protection (CPDP), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria, www.cpdp.bg. You can also complain to the authority where you live or work.
To exercise a right, email hello@sellinger.ai. We may ask you to confirm your identity. We answer within one month, which may be extended by two months for complex requests, and we will tell you if so. Requests are free unless they are manifestly unfounded or excessive. Account holders can also edit their data and delete their account in Settings.
10.1 California and other US states
Residents of California and other US states with privacy laws have the right to know, access, correct and delete personal information, to receive it in a portable format, to opt out of sale, sharing for cross context behavioral advertising and targeted advertising, and not to be discriminated against for using these rights. We do not sell personal information and do not knowingly process data of anyone under 16. In the last 12 months we collected the categories in Section 2 (identifiers, commercial information, internet activity, professional information, audio recordings and inferences) for the purposes in Section 3 and disclosed them to the categories of recipients in Section 7. To opt out of advertising cookies, choose "Essential only" in our cookie banner. You may use an authorized agent. Requests go to hello@sellinger.ai.
11. Security
We protect data with encryption in transit (TLS) and at rest, access controls based on least privilege and row level security, separation of customer Workspaces, logging and monitoring, regular backups, and confidentiality obligations for everyone with access. No system is completely secure. If a personal data breach is likely to result in a risk to you, we will notify the competent authority within 72 hours and inform you where the law requires it.
13. Children
The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
14. Changes to This Policy
We will update this policy when our processing changes. We will tell customers about material changes by email or in the Service before they take effect, and the "Last updated" date always shows the current version.
15. Contact
Sellinger AI OOD, Ring Tower business building No. 1, bl. 621, entr. 1, fl. 3, apt. 1, Mladost district, Sofia 1766, Bulgaria. Email hello@sellinger.ai, phone +359 896 699 009.

