Skip to main content
Home

Legal document

Privacy policy

How we process personal data in Searchlize.

Last updated:

1. General provisions

This Privacy Policy describes how personal data is processed in connection with use of the website and SaaS service named Searchlize(the "Service"). It provides the information required by Articles 13 and 14 of Regulation (EU) 2016/679 (the "GDPR") — both for data you give us directly and for data we obtain from other sources (see section 5).

2. Data controller

The controller of your personal data within the meaning of the GDPR is:

Two roles. We are the controller of your account data, of the technical data generated when you use the Service, and of the business-lead data we independently source and score to provide the prospecting features (see sections 4 and 5). When you use the Service to send outreach from your own mailbox or to sync data to your CRM, we act as a processor on your behalf, and you are the controller — that relationship is governed by our Data Processing Agreement (DPA). For the personal data of third parties that you decide to process for your own purposes (leads, contacts, message content), you may be a separate controller and are responsible for meeting the information and other obligations toward those individuals under the GDPR.

3. Purposes and legal bases for processing

We process personal data for the following purposes and on the following legal bases:

PurposeLegal basis (Art. 6 GDPR)
Account creation and management, provision of the Service (sign-in, configuration, history)Art. 6(1)(b) — performance of a contract
Payments, billing, and defense of contract-related claimsArt. 6(1)(b) — contract; and Art. 6(1)(f) — legitimate interest in pursuing/defending claims
Compliance with legal obligations (e.g., retention of accounting documents)Art. 6(1)(c) — legal obligation
IT security, abuse and fraud prevention, technical and audit logsArt. 6(1)(f) — legitimate interest in keeping the Service secure
Sourcing, verifying, scoring and enriching business-lead data from public and third-party sources so that the prospecting features you requested can operateArt. 6(1)(f) — legitimate interest in providing the B2B prospecting tool and enabling lawful business development; assessed in a documented balancing test and subject to the right to object (section 9)
Browser-side analytics and in-app error reporting (PostHog) using cookies — enabled only after consent via the cookie bannerArt. 6(1)(a) — consent
Server-side product-usage measurement (events pseudonymised by account identifier, no cookies and no personal data in the event payload) to maintain, diagnose and improve the ServiceArt. 6(1)(f) — legitimate interest in measuring and improving how the Service performs; subject to the right to object (section 9)
Newsletter or marketing campaigns addressed to you (if launched)Art. 6(1)(a) — consent

4. Categories of personal data we process

Depending on how the Service is used, the following data may be processed, among others:

  • Account and contact data — the email address used to register, your name, and — if provided — company name, website, phone, tax ID, industry and description; and your authentication data held by our identity provider (including two-factor authentication where you enable it);
  • Billing data processed via the payment operator (e.g., transaction and subscription identifiers, invoice details you provide);
  • Data you enter or generate in the Service — company and lead profiles (name, domain, website, tax/registry identifiers, contact details of individuals, notes, favorites), target groups and campaigns, search queries and saved search sessions, message drafts and sent message content, and integration settings;
  • Device, session and log data — IP address, browser/device identifiers and user-agent, a device hash, approximate location derived from the IP, timestamps and system event identifiers, and push-notification subscription data where you enable browser notifications;
  • Connected-mailbox credentials you provide (OAuth access/refresh tokens or SMTP/IMAP parameters), stored solely to operate the mail and send-queue features and encrypted at rest (AES-256-GCM) in the production environment; they are never returned to the browser and are not included in data exports;
  • Outreach delivery and engagement data — for messages you send through the Service we process delivery events and, where you enable open/click tracking, the recipient's IP address and user-agent together with open/click timestamps. This is personal data of your recipients; you act as controller for it and are responsible for the lawfulness of such tracking;
  • Inbound reply content— the first reply to an outreach message, routed via our email provider's inbound webhook, including the sender address and name, subject and body, and the raw message payload;
  • Website content and metadata retrieved by the search and analysis features from prospect websites (page text, contact details published on the page, technology signals) — to the extent necessary for the Service to operate, including transfer to the AI and search providers listed in section 6.

5. Data we obtain from sources other than you (Art. 14 GDPR)

To provide the prospecting features, the Service collects and processes business-related personal data about companies and the people associated with them ("leads") that we do not obtain from those individuals directly. This section is the information notice required by Art. 14 GDPR for that data.

  • Categories of data:business contact details (name, business email address, phone number, job role where available), employer/company name, website and domain, and public business identifiers such as NIP, REGON, KRS, legal form, PKD code, registered address and headquarters city, along with information derived from the company's public website.
  • Sources — and whether they are publicly accessible: search-engine results (via our search provider), the content of publicly accessible company websites (retrieved automatically), and public official registers — the Central Statistical Office (REGON), the National Court Register (KRS), the Ministry of Finance VAT whitelist — as well as commercial enrichment providers (e.g., Rejestr.io and, optionally, a global B2B database). The registry data comes from publicly accessible sources.
  • Legal basis: Art. 6(1)(f) — our legitimate interest (and that of our customers) in providing a B2B prospecting tool and enabling lawful business development. We document a balancing test and limit the data to what is relevant for business prospecting.
  • Recipients and retention: as described in sections 6 and 8.
  • When we provide this information: in accordance with Art. 14(3), at the latest within one month of obtaining the data, or — if the data is used to contact the person — at the latest at the time of first communication. Because the data is sourced at scale from public sources, providing an individual notice to every person would in many cases involve disproportionate effort within the meaning of Art. 14(5)(b); this public notice, together with the objection mechanism below, is the appropriate measure we take in those cases.
  • Your rights over this data: the rights in section 9 apply, including the right to object at any time (Art. 21) to processing based on legitimate interest. To object or request erasure of lead data concerning you, contact contact@searchlize.com; we will stop processing your data for prospecting unless we demonstrate compelling legitimate grounds.

Where a customer imports or independently sources such data through the Service for their own purposes, that customer is a separate controller and is responsible for its own Art. 14 information duty toward the individuals concerned.

6. Recipients and sub-processors

We disclose personal data only to the providers needed to run the Service, to the independent data sources we query, and to the integrations you connect. Each of our sub-processors acts under a data processing agreement or equivalent processor terms. We do not sell personal data.

Our sub-processors (infrastructure that runs the Service)

ProviderPurposeLocationTransfer safeguard
SupabaseDatabase, user authentication, file storage and realtime.European Union (AWS, Ireland — eu-west-1).Processing within the EEA (European Union).
VercelHosting of the web application and serverless functions.European Union / United States (per configuration).Data processing agreement; Standard Contractual Clauses where data is processed outside the EEA.
UpstashBackground job queue (QStash) and rate-limiting cache (Redis).European Union / United States (per configuration).Data processing agreement; Standard Contractual Clauses where data is processed outside the EEA.
StripePayment and subscription processing.European Union / United States.Standard Contractual Clauses and/or EU-US Data Privacy Framework (where the recipient is certified).
Google (Gemini / Generative AI)AI analysis of website content, lead scoring and generation of message drafts.United States / global.Standard Contractual Clauses and/or EU-US Data Privacy Framework (where the recipient is certified).
OpenRouter (DeepSeek)AI generation of outreach message drafts, routed to the DeepSeek model. Processes lead data and the inputs you provide — never data obtained via Google APIs.United States / global (model inference may occur on DeepSeek infrastructure).Data processing agreement; Standard Contractual Clauses where data is processed outside the EEA.
ResendDelivery of transactional/service email and receipt of the first inbound reply (webhook).United States.Standard Contractual Clauses and/or EU-US Data Privacy Framework (where the recipient is certified).
PostHogProduct analytics. Browser-side capture and error reporting run only after consent to analytics cookies; server-side product-usage events are pseudonymous (account identifier, no cookies, no personal data in the payload).European Union (EU Cloud).Processing within the EEA (European Union).
SentryApplication error and performance monitoring.European Union / United States (per organization).Data processing agreement; Standard Contractual Clauses where data is processed outside the EEA.
Vercel Web AnalyticsCookieless, aggregate visitor and page-view measurement (no cookies, no cross-site tracking, no personal profiles).European Union / United States (per configuration).Data processing agreement; Standard Contractual Clauses where data is processed outside the EEA.
Axiom (optional / when enabled)Log management (where enabled).European Union / United States (per configuration).Data processing agreement; Standard Contractual Clauses where data is processed outside the EEA.

Independent data sources and public registers we query

ProviderPurposeLocationTransfer safeguard
SerperSearch-engine results used to discover company domains (receives the search query).United States.Data processing agreement; Standard Contractual Clauses where data is processed outside the EEA.
Rejestr.ioCommercial enrichment from the Polish court register (KRS) and related data.European Union (Poland).Processing within the EEA (European Union).
GUS / REGON (BIR1)Polish Central Statistical Office register lookup (REGON/NIP business data).Poland.Public statutory register / public authority (Poland).
Ministry of Justice — KRSNational Court Register (KRS) company lookup.Poland.Public statutory register / public authority (Poland).
Ministry of Finance — VAT whitelistVAT/NIP taxpayer verification (biała lista podatników VAT).Poland.Public statutory register / public authority (Poland).
Apollo.io (optional / when enabled)Optional global B2B company/contact database enrichment.United States.Data processing agreement; Standard Contractual Clauses where data is processed outside the EEA.

Services you connect (you direct the transfer)

ProviderPurposeLocationTransfer safeguard
Google (Gmail API)Sending outreach from the Customer's connected Google mailbox (send-only scope).United States / global.Standard Contractual Clauses and/or EU-US Data Privacy Framework (where the recipient is certified).
Microsoft (Outlook / 365)Sending from the Customer's connected Microsoft mailbox; access to the mailbox and profile granted by the Customer via OAuth.European Union / United States.Standard Contractual Clauses and/or EU-US Data Privacy Framework (where the recipient is certified).
HubSpot (optional / when enabled)Two-way sync of lead/contact data to the Customer's CRM.European Union / United States.Standard Contractual Clauses and/or EU-US Data Privacy Framework (where the recipient is certified).
Salesforce (optional / when enabled)Two-way sync of lead/contact data to the Customer's CRM.European Union / United States.Standard Contractual Clauses and/or EU-US Data Privacy Framework (where the recipient is certified).
Pipedrive (optional / when enabled)Two-way sync of lead/contact data to the Customer's CRM.European Union.Processing within the EEA (European Union).
Kommo (optional / when enabled)Two-way sync of lead/contact data to the Customer's CRM.United States.Data processing agreement; Standard Contractual Clauses where data is processed outside the EEA.
Custom SMTP/IMAP server (optional / when enabled)Sending from a mail server configured by the Customer.Determined by the Customer.Under the Customer's own arrangements with the provider.

Cold outreach is typically sent from your own mail infrastructure (a connected mailbox). Browser push notifications, where enabled, are delivered through the push service of your browser vendor. Those providers process data under their own terms.

7. Transfers of data outside the European Economic Area (EEA)

Our database, authentication and product analytics are hosted in the European Union (see section 6). Some providers, however, process data outside the EEA (in particular in the United States). For those transfers we rely on the mechanisms permitted by Chapter V of the GDPR — the EU-US Data Privacy Frameworkwhere the recipient is certified, and otherwise the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) together with, where appropriate, supplementary measures. You can request information about the safeguards applied by writing to contact@searchlize.com.

8. Retention period

  • Account and Service data — for the duration of the agreement and, after it ends, for the period necessary to pursue or defend claims. You can delete your account at any time in the Service; deletion removes your application data (leads, messages, search history, connected-mailbox secrets and related records), typically completed within 30 days;
  • Accounting and tax data — for the period required by tax and accounting law, held by us and/or the payment operator;
  • Lead and enrichment data — retained while you keep it in your workspace; deleted or anonymized on account deletion or on a valid erasure/objection request;
  • Technical logs and analytics — for a period justified by security and product needs and no longer than necessary; backups are purged on the normal backup rotation.

9. Rights of the data subject

You have, among others, the right to:

  • access your data and obtain a copy;
  • rectification (correction) of data;
  • erasure and restriction of processing, within the limits of the GDPR;
  • object to processing based on legitimate interest (Art. 21), including profiling — and, where data is used for direct marketing, to object at any time with absolute effect;
  • data portability, where processing is automated and based on a contract or consent;
  • where processing is based on consent — withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
  • lodge a complaint with the supervisory authority — in Poland, the President of the Personal Data Protection Office (Prezes UODO), ul. Stawki 2, 00-193 Warszawa.

To exercise these rights, contact contact@searchlize.com. We respond within the timeframes set by Art. 12 GDPR (generally within one month).

10. Automated processing and profiling

The Service uses AI models to analyze website content, score leads against your target profile, and generate message drafts. This involves profiling within the meaning of the GDPR. We have assessed that this does not constitute a decision based solely on automated processing that produces legal or similarly significant effects on the data subject within the meaning of Art. 22 GDPR: the scores and drafts are decision support, and the business decisions and whether to send any communication remain with the User, who reviews the output. You may contact us for more information about the logic involved.

AI models and data from Google APIs (Google API Services User Data Policy — Limited Use)

For the features described above we use third-party AI services. To generate message drafts we use the DeepSeek model provided via OpenRouter (model routing); if that service is unavailable, the draft is generated as a fallback by Google Gemini. The other AI features (website content analysis, lead scoring) use Google Gemini (Generative Language API). These models process website content and lead data sourced from public and third-party sources (section 5), as well as data you enter into the Service yourself.

Data obtained from Google APIs. Connecting a Google mailbox uses a send-only scope (gmail.send) together with the account email address (userinfo.email) for mailbox identification. We do not readyour inbox, threads, contacts, or message content through Google APIs. Searchlize’s use and transfer of information received from Google APIs (including Google Workspace) adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, no data obtained through Google APIs is transferred to our AI model providers (Google Gemini, DeepSeek/OpenRouter) or used to train or improve generalized artificial-intelligence models.

11. Cookies and related technologies

The rules for cookies and similar technologies are described in a separate document: Cookie Policy. Note that the open/click tracking of outreach messages (section 4) uses tracking pixels and redirect links rather than cookies on your device.

12. Changes to the Privacy Policy

We may update this policy, in particular when Service features or applicable law change. Material changes will be communicated appropriately (e.g., via a message in the Service or by email).