This Privacy Policy describes how Kairos Labs LLC, a limited liability company organized under the laws of the State of Florida, United States ("Kairos Labs," "we," "us," or "our"), owner and operator of the Seialz brand and platform, collects, uses, stores, shares, and protects personal information in connection with the Seialz platform, a customer relationship management (CRM) software offered as a Software-as-a-Service (SaaS) solution for businesses, available at https://seialz.com and related domains (the "Platform").
By using the Platform, you acknowledge that you have read and understood this Privacy Policy. If you have any questions, please contact us at privacy@seialz.com.
1. OUR ROLES IN PROCESSING DATA
Seialz is a business-to-business (B2B) platform. We act in two distinct capacities:
a) As a Business (Controller). When we process personal information of representatives, users, and contacts of the companies that subscribe to the Platform ("Clients") — such as account registration, billing, authentication, and Platform usage data — Kairos Labs determines the purposes and means of processing.
b) As a Service Provider (Processor). When Clients use the Platform to manage data about their own customers, leads, and contacts ("End Users") — including WhatsApp conversations, contact information, and sales records — Kairos Labs acts solely as a service provider/processor, processing that data on behalf of and under the instructions of the Client, who is the controller of that data. We do not sell End User data, retain it beyond the purposes of the service, or use it for any purpose other than providing the contracted services. Requests from End Users regarding their data should be directed primarily to the responsible Client, without prejudice to our duty to cooperate.
2. INFORMATION WE COLLECT
2.1. Information provided by Clients and their users
- Full name, email address, phone number, and job title of account users;
- Company information: legal name, tax identifiers, address, billing details;
- Login credentials (passwords stored in encrypted form);
- Content entered into the Platform: contacts, deals, tasks, notes, files, and messages.
2.2. End User information processed on behalf of Clients
- Name, phone number, email address, and other contact details;
- Conversation history (including WhatsApp messages exchanged between the Client and its End Users);
- Lead source data (campaigns, ads, forms);
- Pipeline stages, tags, and sales records created by the Client.
2.3. Information collected automatically
- IP address, browser type, operating system, and device identifiers;
- Access logs, timestamps, pages visited, and actions taken on the Platform;
- Cookies and similar technologies (see Section 10).
2.4. Information received from Meta platforms
When a Client connects Meta assets (WhatsApp Business Platform, Facebook, Instagram) to the Platform, we receive — upon the Client's express authorization through Meta's official flows (such as Embedded Signup) — the following data:
- WhatsApp Business Account (WABA) information: identifiers, phone numbers, message templates, quality ratings, and messaging limits;
- Messages sent and received through the WhatsApp Business Platform (Cloud API), including content, delivery metadata, and conversation identifiers;
- Lead data originating from ads (Facebook Lead Ads, click-to-WhatsApp ads), including campaign referral data;
- Basic information about connected pages and ad accounts, to the extent of the permissions granted.
3. HOW WE USE DATA RECEIVED FROM META ("PLATFORM DATA")
We process data received through Meta's APIs and products ("Platform Data") in strict compliance with the Meta Platform Terms and Meta's Developer Policies, as well as the WhatsApp Business Solution Terms. Specifically:
- We use Platform Data solely to provide, maintain, and improve the Platform features contracted by the Client;
- We do not sell Platform Data, nor do we license or share it with data brokers, ad networks, or monetization services;
- We do not use Platform Data to build or supplement user profiles beyond the contracted purpose, nor for surveillance purposes;
- We do not use the content of WhatsApp messages to train general-purpose artificial intelligence models;
- We maintain appropriate technical and organizational security measures to protect this data (see Section 8);
- We delete Platform Data when it is no longer necessary for the provision of the service, upon the Client's request, when required by Meta, or as required by applicable law (see Sections 7 and 9).
4. HOW WE USE YOUR INFORMATION
We process personal information for the following purposes:
- To create and manage accounts, authenticate users, and provide the contracted services;
- To process payments and issue invoices;
- To enable integrations authorized by the Client (Meta, email, telephony, and others);
- To provide technical support and customer service;
- To protect the security of the Platform, and to detect and prevent fraud and abuse;
- To comply with legal and regulatory obligations and respond to lawful requests from public authorities;
- To analyze aggregated Platform usage for product improvement;
- To send marketing communications about the Platform itself, with the option to opt out at any time.
5. HOW WE SHARE YOUR INFORMATION
We do not sell personal information, and we do not share personal information with third parties for cross-context behavioral advertising or targeted advertising purposes, as those terms are defined under applicable U.S. state privacy laws. We share information only in the following circumstances:
a) Service providers and subprocessors, contractually bound to protect the data and use it only under our instructions, in the following categories:
- Cloud infrastructure, hosting, and database providers;
- Meta Platforms, Inc. and its affiliates (to operate the WhatsApp, Facebook, and Instagram integrations authorized by the Client);
- Large language model and artificial intelligence providers, when the Client enables AI features (processing is limited to executing the feature; see Section 3);
- Payment processors and financial tools;
- Analytics, error monitoring, and transactional communication tools (email, SMS).
b) Public authorities, when necessary to comply with a legal or regulatory obligation, court order, subpoena, or other lawful request.
c) Business transfers, such as a merger, acquisition, financing, or sale of assets, in which case the data will remain protected by this Policy and affected individuals will be notified of any material changes.
An updated list of subprocessors is available upon request at privacy@seialz.com.
6. INTERNATIONAL DATA TRANSFERS
Kairos Labs is headquartered in the United States, and our infrastructure providers may store and process data on servers located in the United States or other countries. If you access the Platform from outside the United States, you understand that your information will be transferred to and processed in the United States. Where required by applicable law, we implement appropriate safeguards for international transfers, such as standard contractual clauses. Individuals located in Brazil are also covered by the Brazilian Portuguese version of this Policy, which addresses the requirements of the Lei Geral de Proteção de Dados (LGPD).
7. DATA DELETION
Requests by Clients. Clients may delete data directly within the Platform or request deletion of their account and all associated data by emailing privacy@seialz.com. Upon confirmation, we will delete the data within 30 days, except for data we are required to retain by law (for example, tax and billing records and access logs).
Requests by individuals (End Users). Individuals whose data is processed by a Client through the Platform should direct their request to that Client (the controller of their data). If we receive such a request directly, we will forward it to the responsible Client and cooperate with its fulfillment.
Data from Meta platforms. If you have interacted with the Platform through Meta products and wish to request deletion of your data, send your request to privacy@seialz.com with the subject line "Data Deletion — Meta," identifying the phone number or identifier used. We will confirm once the deletion is complete.
Disconnecting integrations. Clients may revoke the permissions granted to the Platform at any time in their Meta Business Manager settings, which stops the receipt of new data.
8. HOW WE KEEP YOUR INFORMATION SAFE
We adopt technical and organizational measures consistent with industry standards, including:
- Encryption of data in transit (TLS) and at rest;
- Logical data isolation between Clients (multi-tenant architecture with row-level access controls);
- Role-based access control, secure authentication, and audit logging;
- Vulnerability management, backups, and an incident response plan.
However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security. In the event of a security incident involving personal information, we will notify affected individuals and authorities as required by applicable law.
9. DATA RETENTION
We retain personal information only for as long as necessary for the purposes set out in this Policy:
- Account data and Platform content: for the duration of the contractual relationship with the Client and for up to 90 days after termination, to allow data export, unless earlier deletion is requested;
- Access logs: as required for security purposes and by applicable law;
- Tax and billing records: for the periods required by applicable law;
- Platform Data (Meta): only for as long as necessary to provide the service, subject to Meta's policies and the Client's instructions.
After these periods, data is securely deleted or anonymized.
10. COOKIES AND TRACKING TECHNOLOGIES
We use cookies and similar technologies for: (i) essential functions, such as authentication and security; (ii) user preferences; and (iii) usage and performance analytics. You can manage cookies through your browser settings; disabling essential cookies may impair the functioning of the Platform. We do not use third-party advertising or retargeting cookies on the Platform.
11. YOUR U.S. STATE PRIVACY RIGHTS
Depending on your state of residence (including California, Colorado, Connecticut, Delaware, Florida, Montana, Oregon, Texas, Utah, Virginia, and other states with comprehensive privacy laws), you may have the following rights regarding personal information for which we act as the controller/business:
- The right to know whether we are processing your personal information and to access it;
- The right to correct inaccuracies in your personal information;
- The right to delete your personal information;
- The right to obtain a portable copy of your personal information;
- The right to opt out of the sale of personal information, sharing for targeted advertising, and certain profiling (note: we do not sell or share personal information for targeted advertising);
- The right to non-discrimination for exercising your rights;
- The right to appeal a decision regarding your request.
How to exercise your rights. Submit a request to privacy@seialz.com. We will verify your identity before responding and will respond within the timeframes required by applicable law. You may designate an authorized agent to submit a request on your behalf, subject to proof of valid authorization. If we deny your request, you may appeal by replying to our decision; if your appeal is denied, you may contact your state Attorney General.
Note for End Users: if your data is processed by us on behalf of one of our Clients, we will refer your request to that Client, who is responsible for responding as the controller of your data.
Global Privacy Control (GPC). We honor GPC signals as a valid opt-out request where required by applicable law.
Do-Not-Track. Because no uniform standard for DNT signals has been adopted, we do not currently respond to DNT browser signals.
California "Shine the Light." California residents may request information about disclosures of personal information to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.
12. CHILDREN'S PRIVACY
The Platform is intended for business use and is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child in violation of applicable law, we will delete it promptly. If you believe a child has provided us with personal information, please contact us at privacy@seialz.com.
13. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. The current version will always be available on the Platform, with the "Last updated" date indicated at the top. If we make material changes, we will notify you through the Platform or by email.
14. HOW TO CONTACT US
Seialz is a brand of Kairos Labs LLC, a Florida limited liability company.
Email: privacy@seialz.com