Seegnals

Security and data

Your data stays in the EU.

This page is meant to be boring and checkable: where the data sits, who can reach it, how the keys are held, and what happens when you ask for it back.

What we do

Hosting in the EU

Application in Germany, database in Ireland. No transfer outside the EEA for core processing.

Mailbox credentials encrypted

AES-256 at rest, with a key held outside the database. A credential value never reaches a page in any form.

Your model key stays yours

Reply classification runs on a key you provide, encrypted per workspace. Your inbox is not training anybody's model.

Isolation between workspaces

Row-level security in the database, tested. Application code cannot bypass it with one forgotten query.

Data processing agreement

You are the controller of your prospects' data, we are the processor. The standard DPA says so, with the sub-processor list, and so does the Privacy Policy. A countersigned copy on request.

Export and deletion

Suppression list and workspace data exportable in one click. Deletion removes it, it does not flag it.

Volume is moderated.

  • An acceptable use policy from day one. Written before the first incident rather than after it, with hard limits attached to it.
  • Sending is throttled deliberately. Shared reputation is shared: one abusive account degrades every sender on the platform, so volume that looks like a list nobody built gets turned down.
  • Suppression is honoured platform-wide. An address that unsubscribes stops receiving mail from every workspace and every campaign.

Reporting something

Found a vulnerability, or think we are processing something we should not be? Write to privacy@seegnals.com. We answer, and we do not threaten people who tell us about holes.