Privacy Policy
Last updated: August 2026
1. Introduction
SalesMind AI ("we", "us", "our") is a service operated by SalesMind Pte. Ltd. (UEN 202501751Z), a company incorporated in Singapore with its registered office at 160 Robinson Road, #14-04 Singapore Business Federation Center, Singapore 068914. We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at sales-mind.ai and use our AI-powered sales automation services (the "Service").
This Privacy Policy describes our data practices and the legal bases on which we rely for each processing activity. It applies whether or not you have an account with us. Where a specific activity relies on your consent (for example, marketing emails or analytics cookies), we request that consent separately and you may withdraw it at any time; for all other activities we rely on the legal bases set out in Section 4.
2. Information We Collect
2.1 Information You Provide
We collect personal information that you voluntarily provide when you:
- Register for an account or request a demo
- Subscribe to our newsletter or marketing communications
- Contact us through forms, email, or live chat
- Purchase a subscription or service plan
- Apply for a job or partnership
- Connect your LinkedIn account to our platform
This may include your name, email address, phone number, company name, job title, billing information, and LinkedIn profile data.
2.2 Information Collected Automatically
When you visit our website, we automatically collect certain technical information, including:
- IP address and approximate geolocation
- Browser type, version, and language preference
- Operating system and device type
- Referring URLs and exit pages
- Pages visited, time spent, and click patterns
- Cookies and similar tracking technologies (see our Cookie Policy)
2.3 Information From Third Parties
We may receive information from third-party sources, including LinkedIn (when you connect your account), payment processors (Stripe), and analytics providers (Google Analytics, Microsoft Clarity). We also use third-party AI services to enrich and analyze prospect data, including AWS Rekognition for facial analysis (gender and age range inference from profile photos), Google Vertex AI / Gemini for personality analysis, fit-scoring, and outreach content generation, and OpenAI services for message enhancement and assistant features.
2.4 Automated Profiling and AI-Generated Enriched Attributes
Through our Service, we process prospect data using automated decision-making and profiling tools to derive or enrich the following attributes:
- Facial Analysis (Gender and Age Range): AWS Rekognition analyzes profile photos to infer gender and approximate age range. This biometric categorisation is used to personalize outreach tone and messaging (e.g., gendered salutations) and to support personality profiling and fit-scoring algorithms.
- Personality Analysis and Fit Scoring: We use AI services (Google Vertex AI, Gemini, and other third-party providers) to infer personality traits (MBTI-style classifications), professional suitability ("fit" scores), and communication preferences based on available prospect data (name, title, LinkedIn profile, email domain patterns, etc.). These scores are generated automatically without explicit human review and are used to personalize sales messaging.
- Contact Information Enrichment: We enrich prospect records with additional email addresses (personal and professional), phone numbers, and other contact details sourced from third-party data providers (FullEnrich, Icypeas, and similar enrichment services).
Sources: Prospect data originates from publicly accessible sources (in particular, public LinkedIn profile information), from CRM systems our customers choose to connect, and from the enrichment integrations described in this Policy.
Legal Basis: These processing activities are necessary for our legitimate interests in delivering effective, personalized sales outreach and improving our Service (GDPR Article 6(1)(f)). We balance these interests against your rights, and your profile data (including photos) may be subject to automated analysis when accessed through our Service. This processing is supported by a documented Legitimate Interest Assessment (LIA) and Data Protection Impact Assessment (DPIA); a summary is available on request.
Your Rights: You have the right to object to this profiling and automated decision-making at any time by contacting privacy@sales-mind.ai. Upon receipt of an objection, we will flag your record and cease automated processing for profiling and fit-scoring purposes in future outreach. You also have the right to request access to, rectification of, or deletion of any inferred or enriched attributes we hold about you.
Retention: Inferred attributes (gender, age range, personality scores, fit scores) are retained for the duration of your record in our system, for a maximum of 24 months from last contact, after which they are purged alongside your prospect record. You may request earlier deletion at any time.
3. How We Use Your Information
We process your personal data for the following purposes:
- Service delivery: Provide, operate, and maintain the SalesMind AI platform and its features
- Profiling and automated personalization: Derive personality traits, fit scores, and demographic inferences (gender, age range) from prospect data to personalize sales messaging, improve targeting, and train AI models used in outreach generation
- Account management: Create and manage your user account, process payments, and handle billing
- Communication: Send transactional emails, respond to inquiries, and provide customer support
- Marketing: Send promotional communications about our products and services (only with your explicit consent)
- Analytics: Understand usage patterns, improve our Service, and develop new features
- Security: Detect, prevent, and address fraud, abuse, and technical issues
- Legal compliance: Comply with applicable laws, regulations, and legal processes
4. Legal Basis for Processing (GDPR)
Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:
- Contract performance: Processing necessary to deliver the Service you have subscribed to (Article 6(1)(b))
- Consent: Where you have given explicit consent for specific processing activities, such as marketing emails and analytics cookies (Article 6(1)(a))
- Legitimate interests: Processing necessary for our legitimate business interests, such as fraud prevention, service improvement, profiling for personalized sales outreach, and automated fit-scoring, provided these do not override your fundamental rights (Article 6(1)(f)). Biometric categorisation via facial analysis (AWS Rekognition gender/age inference) is processed under this legal basis and is subject to the AI Act Article 50(3) transparency notice in this Policy
- Legal obligation: Processing required to comply with applicable laws and regulations (Article 6(1)(c))
5. Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience and collect analytics data. Non-essential cookies are only activated after you provide consent through our cookie banner.
For detailed information about the cookies we use and how to manage your preferences, please refer to our Cookie Policy.
6. Data Sharing and Third Parties
We do not sell your personal information. We may share your data with the following categories of third parties:
- Service providers: Cloud hosting providers, payment processing (Stripe), email delivery, and customer support tools
- Analytics providers: Google Analytics (GA4) and Microsoft Clarity for website usage analysis (consent-gated)
- Platform integrations: LinkedIn, Customer Relationship Management (CRM) systems (HubSpot, Pipedrive, LeadConnector (GoHighLevel)), and other services you choose to connect
- Legal authorities: When required by law, court order, or governmental regulation
- Business transfers: In connection with a merger, acquisition, or sale of assets, with prior notification to affected users
Sub-Processors
The following providers process personal data on our behalf to deliver the Service. We maintain data processing agreements with each of them and update this list as our infrastructure evolves:
| Provider | Purpose | Region |
|---|---|---|
| MongoDB Atlas | Primary database | EU (Stockholm, AWS eu-north-1) |
| AWS | File storage (S3) with CloudFront delivery; facial analysis (Rekognition) | EU (Paris eu-west-3; Ireland eu-west-1) |
| Platform.sh / Upsun | Application backend (API) hosting | EU (Sweden, AWS) |
| Vercel | Website and application frontend hosting | Global (US) |
| Google Cloud | Firestore database (eur3); Cloud Functions incl. payments and link tracking (europe-west1); BigQuery analytics export (us-central1); Firebase Authentication; Vertex AI / Gemini inference (global endpoint) | EU + US |
| OpenAI | AI message generation and assistant features | US |
| S-MIT | Dedicated servers hosting our AI workflow orchestration, message queue, realtime, and MCP services | France (EU) |
| Bright Data | Web data collection for prospect enrichment (via our AI workflows) | Israel (EU adequacy decision) / global network |
| Stripe | Payment processing | US (DPF) |
| Mailgun | Transactional email | US |
| Intercom | Customer support chat | US |
| PostHog | Product analytics | US |
| Google Analytics (GA4) & Microsoft Clarity | Website analytics (consent-gated) | US |
| Supabase | Website and companion app databases | Australia (ap-southeast-2) and Singapore (ap-southeast-1), AWS |
| LeadConnector (GoHighLevel) | CRM integration and demo booking | US |
User-Managed Enrichment Services
If you provide your own API credentials to third-party enrichment services (such as FullEnrich or Icypeas) for prospect email, phone, or additional profile data, those services act as sub-processors of personal data under your instructions. In such cases:
- You remain the data controller for enrichment requests
- We act as a processor on your behalf, relaying your enrichment requests to the vendor
- The enrichment vendor processes prospect data according to their own terms and privacy policies
- You are responsible for ensuring that the vendor has appropriate data processing agreements in place and complies with applicable data protection laws (GDPR, CCPA, PDPA, etc.)
We recommend reviewing the privacy and data processing terms of any enrichment vendor before providing your API credentials:
- FullEnrich Privacy & DPA — email/phone enrichment
- Icypeas Privacy & DPA — email/phone enrichment
We do not list these vendors in our primary sub-processor disclosure because you control the integration directly via your own API key; their DPA obligations run to you, not to us. If you wish to disable enrichment or switch vendors, you may remove your API credentials at any time in your account settings.
7. International Data Transfers
Your personal data is primarily hosted on cloud infrastructure located in the European Union (for example, AWS eu-north-1 and eu-west regions, and Google Cloud europe-west1 / eur3). Some processing takes place outside the EU: certain providers host data in the United States, Australia, or Singapore; some AI inference requests (for example, Google Vertex AI via its global endpoint, and OpenAI) may be processed in the United States or other regions; and our own team operates from Singapore.
Where personal data is transferred outside the EEA or the United Kingdom, we rely on the following safeguards under GDPR Articles 44–49:
- EU Standard Contractual Clauses (SCCs): We rely on the European Commission’s Standard Contractual Clauses (2021), which are incorporated into the data processing agreements of our major providers, including AWS, Google Cloud, and OpenAI
- EU–U.S. Data Privacy Framework (DPF): Where a U.S. provider is certified under the DPF, we may additionally rely on that certification
- Supplementary measures: Encryption in transit and at rest, access controls, and EU-region hosting by default where the provider offers it
You may request a copy of the relevant transfer safeguards by contacting privacy@sales-mind.ai.
Government access requests: In line with Chapter VII of the EU Data Act, we take reasonable technical, organizational, and legal measures to prevent unlawful third-country government access to data we hold. We do not disclose data to any authority unless legally compelled through a valid and binding procedure, we review every request before responding, and where legally permitted we will inform affected customers.
8. Data Security
We apply layered technical and organizational safeguards to protect your personal data:
- Encryption in transit: All data exchanged with our website, applications, APIs, and third-party integrations is encrypted using TLS (HTTPS) — including integration credentials and session tokens, which are only ever transmitted over encrypted channels
- Encryption at rest: Our databases and file storage are hosted on cloud infrastructure that encrypts all data at rest at the storage level (AES-256), including MongoDB Atlas managed databases
- Credential handling: We do not store your passwords — platform authentication is delegated to a dedicated identity provider (Firebase). We do not store email (IMAP/SMTP) credentials. Third-party integration tokens are held in access-controlled systems and used only to deliver the features you enable
- Access controls: Production access is restricted to authorized personnel on a need-to-know basis; API access is authenticated, scoped, and rate-limited
- Monitoring and review: We log security-relevant events and regularly review our security practices
- Incident response and breach notification: We maintain an incident response procedure. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where required (GDPR Article 33) and inform affected users without undue delay (GDPR Article 34)
No method of transmission or storage is 100% secure and we cannot guarantee absolute security, but we are committed to protecting your data and to transparent communication if an incident occurs.
9. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy:
- Active accounts: Data is retained for the duration of your account plus 30 days after closure for data export
- Prospect records: Prospect profiles and inferred attributes (see Section 2.4) are retained for a maximum of 24 months from last contact, after which they are purged
- Marketing contacts: Until you unsubscribe or withdraw consent
- Financial records: 5 years as required by Singapore commercial law
- Analytics data: Anonymized after 26 months
10.1 Automated Decision-Making, Profiling, and Article 22 Rights
We use automated decision-making and profiling (as described in Section 2.4) to personalize sales outreach and generate targeting recommendations. Under GDPR Article 22, you have the right not to be subject to automated decision-making that produces legal or similarly significant effects on you.
While personality analysis, fit-scoring, and gender/age inference are generated automatically, our users decide who is contacted: they define the target audience, configure the campaign, and approve the messaging approach. Depending on the mode they select, individual messages may be reviewed before sending or sent automatically within the parameters they set. These inferred attributes personalize the content of outreach; they do not by themselves produce legal or similarly significant effects on you. You have the right to:
- Request explanation of the logic, significance, and consequences of any automated processing of your data.
- Object to profiling and automated fit-scoring at any time by contacting privacy@sales-mind.ai.
- Request human review and manual assessment if you believe automated processing has resulted in inaccurate or unfair profiling.
Upon receipt of an objection or request for human review, we will flag your record and cease automated profiling in subsequent processing. We will not use your inferred attributes to generate personalized outreach or fit scores until your objection is resolved.
Exercise Your Rights: Contact privacy@sales-mind.ai with the subject line "Objection to Automated Profiling" to exercise any of these rights. We will respond within 30 days as required by GDPR Article 12.
10.2 Your Rights Under GDPR
If you are located in the European Economic Area (EEA), you have the following rights regarding your personal data:
- Right of access: Request a copy of the personal data we hold about you
- Right to rectification: Request correction of inaccurate or incomplete data
- Right to erasure: Request deletion of your personal data ("right to be forgotten")
- Right to restrict processing: Request limitation of how we process your data
- Right to data portability: Receive your data in a structured, machine-readable format
- Right to object: Object to processing based on legitimate interests or for direct marketing
- Right to object to profiling: Object to automated profiling and fit-scoring used to personalize sales outreach by contacting privacy@sales-mind.ai. Your record will be flagged do-not-profile and automated enrichment will cease
- Right to withdraw consent: Withdraw your consent at any time where processing is based on consent
To exercise any of these rights, please contact us at privacy@sales-mind.ai. We will respond to your request within 30 days as required by GDPR.
You also have the right to lodge a complaint with the Personal Data Protection Commission (PDPC) of Singapore or your local supervisory authority.
Data export and switching: Customers can export their data (leads, conversations, campaign data) from the platform, and we will provide account data in a structured, commonly used, machine-readable format on request, in line with GDPR Article 20 and the EU Data Act. We do not charge fees for data export.
10.3 US State Privacy Rights
If you are a resident of California or another US state with a comprehensive privacy law (such as Virginia, Colorado, Connecticut, or Texas), the following applies:
- No sale or sharing: We do not "sell" personal information and do not "share" it for cross-context behavioral advertising, as those terms are defined by the California Consumer Privacy Act as amended by the CPRA
- Your rights: You may request access to, correction of, or deletion of your personal information, and you will not be discriminated against for exercising these rights
- Sensitive personal information: We do not use or disclose sensitive personal information for purposes that would trigger a "limit use" right under the CPRA
To exercise any of these rights, contact privacy@sales-mind.ai. Authorized agents may submit requests on your behalf with proof of authorization.
11. Children’s Privacy
SalesMind AI is a B2B service not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will promptly delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. For significant changes, we will send a notification to your registered email address.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
- Email: privacy@sales-mind.ai (General inquiries, rights requests, objections to profiling)
- Data Protection Officer (DPO): dpo@sales-mind.ai
- Data Controller: SalesMind Pte. Ltd. (UEN 202501751Z)
- Registered office: 160 Robinson Road, #14-04 Singapore Business Federation Center, Singapore 068914
Privacy Rights Process: For GDPR rights requests (access, rectification, erasure, objection to profiling), send an email to privacy@sales-mind.ai with:
- Your full name
- The email address or LinkedIn profile associated with your record (if known)
- A clear description of your request (e.g., "Objection to automated profiling" or "Request to access inferred attributes")
We will acknowledge receipt of your request and respond with a substantive reply within 30 days as required by GDPR. If your request is complex or we need clarification, we may extend the deadline by an additional 60 days, which we will communicate to you.