Privacy Policy
How Sequenz collects, uses, shares and protects personal data, and the rights you have over it under the EU and UK GDPR.
On this page
Controller: Sequenz Ltd (the "Company", "we", "us")
Sequenz Ltd is a private company limited by shares, registered in England and Wales under company number 17499883. Registered office: 128 City Road, London, EC1V 2NX, United Kingdom. It is the controller of the personal data described here. "Sequenz" is the name of its Service.
Privacy contact: privacy@sequenz.ai
Effective date: 7 October 2026 (version 1.16) Version: 1.16
This Privacy Policy is issued under Articles 13 and 14 of the EU General Data Protection Regulation (GDPR). It describes how the Company processes personal data in connection with the Sequenz platform (the "Service") — an AI-assisted sales-outreach platform.
1.Two distinct roles: when we are controller, and when we are processor
Our role under the GDPR depends on whose data is being processed.
- We are the controller of the personal data of our own customers and their users — i.e. the people who register for, log in to, are billed for, and operate the Service (account holders, team members, billing contacts). This Policy governs that processing.
- We are a processor of the lead / prospect personal data that a customer organisation uploads, syncs, or generates inside their workspace to run outreach. For that data, the customer organisation is the controller — they decide what data to process and why. Our obligations to that customer are set out in our Data Processing Agreement (DPA), not this Policy. Prospects whose data a customer processes through the Service should direct rights requests to that customer; we will assist the customer in responding (see Section 8).
This Policy primarily addresses our processing as controller of account-holder data, and explains the prospect-data processing for transparency.
Back to top2.Categories of personal data we process
2.1Account-holder data (we are controller)
| Category | Data elements | Source |
|---|---|---|
| Identity & account | name, business email, avatar, organisation/workspace name, authentication identifiers (via Clerk) | You / your employer; Clerk on sign-up |
| Authentication & security | session metadata, login events, IP address, two-factor secrets (admin accounts), audit-log entries (action, target, IP, user-agent, timestamp) | Generated by the Service |
| Billing | billing contact, organisation name, subscription tier, invoice history, payment metadata (card data is held by Stripe, not by us) | You; Stripe |
| Connected-account credentials | encrypted OAuth tokens for your own Gmail/Outlook mailbox, HubSpot/Salesforce/Pipedrive, Google Sheets, Calendly, and Meta WhatsApp Business connections | You, via OAuth consent |
| Usage & product analytics | pseudonymous feature-interaction events, page views, product-usage telemetry | Generated as you use the Service (PostHog, EU region) |
| Session replay | a masked reconstruction of your own screen: layout, cursor movement, clicks, scrolling, which dialogs opened, timing. All text and all form input is masked before it leaves your browser — see §2.1a | Generated as you use the Service (PostHog, EU region) |
| Support & communications | messages you send us, onboarding interactions | You |
2.1aWhat session replay does and does not record
With your consent we record a masked replay of your own use of the Service, so we can see where the product is confusing or slow without having to ask you.
What is recorded: page layout, cursor movement, clicks and rage-clicks, scrolling, which dialogs and menus you opened, which step you stopped on, and how long things took.
What is not recorded: any readable text. Every text element and every form field — including anything you type — is replaced with a masked block in your browser, before the recording is transmitted. Network request and response bodies are never recorded, and browser console output is never recorded. A replay therefore shows the shape of a screen and what you did on it, and no content.
This matters most for the prospect data your workspace holds: a replay of the leads table or the unified inbox shows rows and columns, never a prospect's name, email address, phone number or the text of their reply. We do not receive that data through session replay, and we cannot un-mask a recording after the fact.
Replay runs only after you opt in to analytics in the cookie banner, and stops immediately if you withdraw that consent. Recordings are held by PostHog in the EU region and are deleted on the retention schedule in §5.
2.2Prospect / lead data (customer is controller; we are processor)
Customers process the following categories of their business prospects' data through the Service. We process it only on the customer's documented instructions under the DPA:
- Contact identity: business email, first/last/full name, job title, seniority, phone number, LinkedIn profile URL.
- Company: company name, company domain, industry, company size.
- Geography: location, time zone.
- Outreach metadata: email/LinkedIn/WhatsApp send, open, click, reply, and bounce events; sequence enrolment state.
- Communication content: rendered outbound message bodies and subjects across email, LinkedIn, and WhatsApp.
- Consent & suppression: WhatsApp opt-in records (timestamp, source, consent-text version), unsubscribe events, per-workspace suppression entries.
We do not sell prospect data, do not operate a proprietary contact database, and do not enrich prospects from a Company-owned data source.
Back to top3.Purposes and legal bases (Article 6)
| Processing activity | Whose data | Legal basis |
|---|---|---|
| Providing, operating, and securing the Service | Account holders | Contract — Art. 6(1)(b) |
| Billing, invoicing, tax records | Account holders / billing contacts | Contract — Art. 6(1)(b); Legal obligation — Art. 6(1)(c) |
| Security, fraud prevention, audit logging | Account holders | Legitimate interests — Art. 6(1)(f); Legal obligation under Art. 32 |
| Product analytics & improvement | Account holders | Legitimate interests — Art. 6(1)(f) (pseudonymous; see Cookie Policy) |
| Service communications (onboarding, receipts, security alerts) | Account holders | Contract — Art. 6(1)(b) |
| B2B outbound outreach to business prospects | Prospects (on customer's behalf) | The customer relies on legitimate interests — Art. 6(1)(f) — for B2B cold outreach, balanced against the prospect's rights and supported by a one-click unsubscribe mechanism. The customer is responsible for the lawfulness of this basis. |
4.Sub-processors and recipients of personal data
We engage the sub-processors below to deliver the Service. Each is bound by a data-processing agreement (for Northflank, our hosting provider, the agreement is being executed); the current authoritative list (with legal entity, purpose, region, and DPA link) is published on our Compliance posture page and reproduced in the DPA. There are currently 22 sub-processors:
Platform infrastructure: Clerk, Inc. (authentication); Stripe, LLC (billing); Plus Five Five, Inc. / Resend (transactional email — not campaign sends); Functional Software, Inc. / Sentry (error monitoring); PostHog, Inc. (product analytics, EU Frankfurt); Vercel, Inc. (frontend hosting); Northflank Ltd. (backend + worker hosting + primary PostgreSQL database, EU region); Upstash, Inc. (managed Redis queues, EU); OpenAI OpCo, LLC (AI-written drafts, reply sorting and the in-app assistants — no training on customer data via API); Bouncer (usebouncer.com, a check of the recipient's email domain before sending — it receives the domain only, never the full address); Cloudflare, Inc. (R2 object storage for exports); IPRoyal Services FZE LLC (UAE, Ajman — dedicated egress IP for LinkedIn automation, where you have connected a LinkedIn account; the IP itself is located in the country you declared. The provider carries encrypted traffic and does not see message content. Transfers outside the EEA are covered by the EU Standard Contractual Clauses); Bright Data Ltd. (Israel, Netanya — the same service for the United Arab Emirates and Saudi Arabia, which the provider above does not cover. Israel benefits from an EU adequacy decision, so no additional transfer safeguards are required).
Customer-connected integrations: HubSpot, Inc.; Salesforce, Inc.; Pipedrive OÜ (CRM sync); Calendly LLC (meeting ingestion); Google LLC (Gmail: sending from your own mailbox and reading replies to your campaigns; Google Sheets lead import); Microsoft Corporation (Outlook send via Microsoft Graph, your own mailbox); the Company-operated Chrome extension telemetry endpoint (LinkedIn); Meta Platforms, Inc. (WhatsApp Business Cloud API).
We notify customers at least 30 days before adding or replacing a sub-processor, and the customer may object (see the DPA).
4.1Google user data — Limited Use
This section covers the data Sequenz receives from Google when you connect your own Google account. It is shown in short form in the app, directly before every Google sign-in.
What we access, and why
Gmail access (restricted scopes) is requested when you connect a Gmail mailbox, or when you tick "Also send campaign email from this Google account" while connecting Google Sheets. Google Sheets access (a sensitive scope) is requested when you connect Google Sheets.
gmail.send: to send the campaign emails and replies you approve, from your own address.gmail.readonly: to read replies and bounce notices in the email threads Sequenz started, so that a sequence stops when someone answers, the conversation shows in your Sequenz inbox, and replies and bounces are sorted. Google's consent screen describes this scope as reading your email; Sequenz only opens threads it started, by their ID, and does not search or list the rest of your mailbox.spreadsheets.readonly: to read the rows of the sheets you add, and import them as leads. Sequenz never edits your sheets.
Where it goes. Google user data is stored on our backend in the EU (Northflank: database and application servers; Upstash: short-lived processing queues). Email text read through Gmail reaches these recipients only:
- OpenAI, in two cases: when you open a reply with AI reply drafts turned on (the default), to draft an answer; and when a bounce notice is unclear, to tell an out-of-office reply from an address that no longer exists. We remove identifiers the task does not need (email addresses, phone numbers, IP addresses) before sending, we ask OpenAI not to store the request, OpenAI does not use it to train its models, and a draft is never sent without your click.
- Your own CRM, if you connect one: each reply is logged there as a "Reply received" activity with its first words.
- You: the first words of a reply appear in your in-app notifications, and in the email we send you when a campaign gets its first reply (sent through Resend). Webhooks you configure receive only identifiers, the sender's address, the time and the reply category — never the reply's text.
Rows imported from Google Sheets become leads in your workspace and are handled like the rest of your lead data (Section 2.2): for example, they can be used to write your campaign emails and synced to your CRM.
Our commitments. Sequenz's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements. In particular:
- We use Google user data only to provide and improve the user-facing features described above, which are prominent in the Service's interface.
- We do not transfer or sell Google user data to third parties such as advertising platforms, data brokers or information resellers; we do not use it for advertising or to decide creditworthiness or lending; and we do not use it to develop, improve or train generalised or non-personalised AI or machine-learning models.
- People at Sequenz do not read your Google user data, except: (a) where necessary for security purposes, such as investigating abuse; (b) to comply with applicable law; or (c) for our internal operations, once the data has been aggregated and anonymised. We do not ask for permission to read individual messages, so that exception is never used.
- OAuth tokens are encrypted at rest (AES-256-GCM).
Disconnecting and deletion
- Disconnecting a Gmail mailbox (Mailboxes → ⋯ → Disconnect): we stop using it, delete the email text we stored from it (reply bodies, your messages in those threads, inbox excerpts and AI reply drafts), revoke our access at Google (unless another Sequenz connection still uses the same Google account) and delete the stored tokens. This usually takes minutes; if a step fails, it is retried automatically every day until it completes. If the same Google account is connected for Google Sheets, that connection then needs reconnecting. Reply excerpts already written into your own CRM stay there, and a copy held in a failed background task is removed within 14 days.
- Disconnecting Google Sheets (on the Google Sheets page (type "Google Sheets" in the ⌘K command bar to open it)): we delete the stored tokens at once and ask Google to revoke our access, unless another Sequenz connection still uses the same Google account. Leads already imported stay in your workspace, and each sheet you added stays listed (its link and column choices) until you remove it there.
- Removing Sequenz in your Google Account (myaccount.google.com/permissions): our access ends at once. To also delete the email text we stored, disconnect the mailbox in Sequenz.
- When Google reports a security event: Sequenz is registered for Google's Cross-Account Protection. If Google tells us that access to a connected Google account was revoked or that the account was disabled (for example after a hijacking), we mark its mailboxes and Google Sheets connections as needing reconnection, delete their stored tokens and pause the campaigns sending from them. This applies to Google connections made or reconnected from 27 September 2026; an older connection is covered once it is reconnected. We keep a record of each event (Google's account id and the event type, no email content) for 90 days after we act on it.
- Deleting your account: we ask Google to revoke every Google connection you made, in any workspace, and delete its stored tokens. Workspaces only you are in are deleted with your account; workspaces other people use stay with them (see Section 6).
5.International transfers
Our primary data store is hosted in the EU (Northflank), and EU-region options are enabled where available (e.g. PostHog EU). Several sub-processors are established in the United States or operate globally. Where personal data is transferred outside the EEA, we rely on:
- an adequacy decision (e.g. the EU–US Data Privacy Framework, where the recipient is certified); or
- the European Commission's Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914 of 4 June 2021, supplemented by a transfer-risk assessment where required; and
- for transfers subject to the UK GDPR, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs issued by the Information Commissioner, since the EU SCCs alone do not cover UK transfers.
Transfers between the EEA and the United Kingdom need no additional safeguard: the European Commission renewed its UK adequacy decisions on 19 December 2025, valid until 27 December 2031.
You may request a copy of the relevant transfer safeguards from privacy@sequenz.ai.
5.1Our representative in the EU (Article 27)
The Company is established in the United Kingdom, which is outside the EU/EEA. Note that where our data is hosted does not change this — our primary data store is in the EU, but that is a question of where data sits, not of where we are established.
Because we are established outside the Union and offer the Service to, and monitor the behaviour of, people in the EU/EEA, Article 27 GDPR requires us to designate a representative in the Union — a contact point that EU data subjects and supervisory authorities can address instead of us. (The reverse obligation does not arise: being UK-established, we need no UK representative.)
We have not yet designated one. The representative will be appointed before the Service is offered to customers in the EU/EEA, and this section will name them with their address and contact details. Until then, privacy enquiries reach us directly at privacy@sequenz.ai, and nothing in this section limits your right to complain to your own supervisory authority (see Section 8).
Back to top6.Retention
| Data | Retention |
|---|---|
| Account-holder identity & workspace | Life of the account, then deleted 30 days after a deletion request (you can cancel until then; you are signed out and your connections are revoked straight away). Workspaces only you are in are deleted with the account; workspaces other people use stay with them |
| Billing & invoice records | 6 years (held principally at Stripe) |
| Audit logs (admin + GDPR action log) | Admin action log: 2 years. GDPR action log (the record that your requests were handled): 6 years. Append-only, then deleted a whole month at a time |
| Aggregate, de-identified engagement metadata | 12 months |
| Activity Control override audit log | 12 months |
| Prospect / lead data (processor role) | Per the customer's instruction and retention settings; engagement events are deleted on the workspace's retention horizon; lead identity is retained while the workspace is active and anonymised within 30 days of the workspace's closure; immediate deletion on unsubscribe or a right-to-erasure request |
| Connected-account OAuth tokens | Until you disconnect the integration or close the account; then revoked at the provider where the provider allows it (Google) and deleted |
| Email text read from or sent through a connected mailbox (reply and message bodies) | Kept while the workspace is active, unless a workspace admin sets a retention period of 7, 30 or 90 days (Settings → Data & privacy), after which bodies are deleted; subject lines are kept until the mailbox is disconnected or the data is erased; everything is deleted when the mailbox is disconnected |
| Inbox excerpts and AI reply drafts | Until the mailbox is disconnected, the prospect's data is erased, or the account is deleted |
| Reply excerpts prepared for reply sorting | A cached block of up to 30 excerpts of up to 280 characters each, kept for at most 24 hours and rebuilt from the replies still stored |
| Google security events (Cross-Account Protection) | 90 days from receipt |
7.Cookies and similar technologies
We set strictly-necessary cookies for authentication/session management (via Clerk) and, with your consent, use EU-region product analytics and masked session replay (PostHog) and error monitoring (Sentry). We do not set marketing or advertising cookies. See our Cookie Policy for the full breakdown and how to manage your choices, and §2.1a for exactly what a session replay does and does not contain.
Back to top8.Your rights as a data subject
Where we are controller of your data, you have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and objection (Art. 21), plus the right not to be subject to solely automated decisions with legal effect (Art. 22).
How to exercise them:
- Account holders — use Data & GDPR settings in-app (
/settings/data-privacy) to request a machine-readable export (Art. 20) or to initiate account deletion (Art. 17). Note: to deter bulk data-scraping, the machine-readable export is not available for accounts less than 7 days old. You may also email privacy@sequenz.ai. - Prospects contacted through a customer's workspace — use the unsubscribe link in any outbound email (the address is suppressed before the next send — Art. 21), or contact the customer organisation that initiated the outreach. We will assist that customer in fulfilling access, rectification, erasure, and portability requests as their processor.
We respond within one month (Art. 12(3)), extendable by two further months for complex requests.
You also have the right to lodge a complaint with a supervisory authority. Because we are established in the UK and not in the Union, the GDPR's "one-stop-shop" does not apply to us and we have no single lead supervisory authority in the EU/EEA — so if you are in the EU/EEA, go directly to the data protection authority of the member state where you habitually live, where you work, or where you believe the infringement took place. In the UK, that authority is the Information Commissioner's Office (ICO). Appointing the representative described in Section 5.1 gives you an additional contact point; it does not change which authority is competent.
Back to top9.Automated processing and AI
The Service uses AI (OpenAI models) to draft outreach content and assist with personalisation, to draft answers to Gmail and Outlook replies you open (when AI reply drafts are on), and to read unclear bounce notices. This is assistive: a human user reviews and sends. We do not use AI to make decisions producing legal or similarly significant effects on prospects within the meaning of Article 22. Prospect data sent to OpenAI via the API is not used to train OpenAI's models (the API's no-training setting), we enable the API's no-storage flag on all model calls that support it, and we redact identifiers (email addresses, phone numbers, IP addresses) from free text before it is sent where they are not needed for the task; OpenAI may retain API data transiently for abuse-monitoring under its terms.
Back to top10.Security
We apply technical and organisational measures appropriate to the risk (Art. 32), including AES-256-GCM encryption of stored credentials, TLS 1.3 in transit, PostgreSQL row-level security for tenant isolation, role-based access control, structured logging with PII redaction, and a documented breach-response process (notification within 24 hours to the controller / 72 hours to the supervisory authority where applicable). See our Compliance posture page.
Back to top11.Children
The Service is a B2B product not directed at children and is not intended for anyone under 18.
Back to top12.Changes to this Policy
We will post any changes on this page and update the version and effective date. Material changes affecting account holders will be notified by email or in-app.
Back to top13.Contact
Sequenz Ltd, 128 City Road, London, EC1V 2NX, United Kingdom · company number 17499883
Privacy contact: privacy@sequenz.ai
Back to top