1. Who is responsible for your data?
Seylac is the controller for personal data processed through the Seylac website and workspace, unless a separate agreement states otherwise.
Privacy questions and data-rights requests can be sent to privacy@seylac.com.
2. Data we process
Account and identity data
Name, email address, password credentials in protected form, account role, verification status, login history and security events.
Company and workspace data
Company profile, team members, customers, vendors, invoices, expenses, payments, banking records, bookkeeping entries, tax settings, files and information entered into the workspace.
Communication and support data
Messages, support requests, feedback and correspondence with Seylac.
Technical and usage data
IP address, browser and device information, timestamps, session identifiers, audit logs, error reports and interactions needed to operate, secure and improve the service.
AI assistant data
Prompts, generated previews, confirmation actions and related audit records. When a user asks for current public information, the question may be sent to an AI and web-search provider. Seylac is designed not to include private company records in a public web-search request.
3. Why we process personal data
- To create and manage accounts and company workspaces.
- To provide invoicing, expense, bookkeeping, reporting, payment and AI-assisted features.
- To authenticate users, prevent fraud, protect accounts and maintain audit records.
- To respond to support requests and communicate service information.
- To comply with accounting, tax, legal and regulatory obligations.
- To diagnose problems, understand service performance and improve Seylac.
Depending on the activity, processing is based on performance of a contract, compliance with a legal obligation, legitimate interests such as service security, or consent where consent is required.
4. AI and automated assistance
Seylac AI can prepare customer, invoice, expense and vendor-bill previews and answer questions about workspace information. A record is not saved until an authorised user confirms the preview.
AI output can be incomplete or incorrect. Users remain responsible for reviewing information before creating records, issuing invoices, filing taxes or making business decisions. High-risk actions such as deleting records, sending funds, approving payments or changing permissions are not completed through the AI assistant.
5. Service providers and data sharing
We may use carefully selected providers for hosting, email delivery, security, customer support, payment integrations and AI functionality. They process data only for the agreed service and under appropriate contractual and security obligations.
We may also disclose information when required by law, to protect users or the service, during a corporate transaction, or when you instruct us to connect a third-party integration.
We do not sell personal data.
6. International data transfers
Some service providers may process data outside your country or region. Where required, we use recognised safeguards such as adequacy decisions, contractual protections and additional security measures.
7. How long we keep data
We retain data only for as long as needed to provide the service, protect accounts, resolve disputes and meet accounting, tax and legal obligations. Retention depends on the type of record, workspace status, contractual requirements and applicable law.
When data is no longer required, it is deleted, anonymised or securely isolated unless continued retention is legally required.
You can initiate account deletion inside the Seylac Android app or from our public account deletion page. After identity verification, account credentials, mobile access tokens and associated personal profile data are deleted or anonymised. Business accounting, tax, audit, security and anti-fraud records may be retained only where a legitimate legal or security obligation requires it; retained records are access-restricted and do not keep the app account active.
8. Security
We use access controls, company isolation, role-based permissions, secure sessions, encryption in transit, audit logging, backups and other technical and organisational measures designed to protect information. No online service can guarantee absolute security, so users must also protect passwords and devices.
9. Your privacy rights
Subject to applicable law, you may have the right to:
- Receive information about how your personal data is processed.
- Access and obtain a copy of your personal data.
- Correct inaccurate or incomplete information.
- Request deletion or restriction of processing.
- Object to certain processing.
- Receive portable data where the right applies.
- Withdraw consent without affecting earlier lawful processing.
- Complain to a data protection authority.
Requests can be sent to privacy@seylac.com. Account deletion can also be started from the dedicated deletion page. We may need to verify your identity before responding.
You may contact the data-protection or privacy authority responsible for your country or region. Finland-specific authority information is provided only when a Finland-specific service applies.
10. Children
Seylac is a business service and is not directed to children. Users must have legal authority to create an account and act for the company or organisation they represent.
11. Changes to this policy
We may update this policy when the service, providers or legal requirements change. The updated date will appear at the top of this page. Material changes may also be communicated in the workspace or by email.
Privacy question?
Contact the Seylac privacy team.