1. Who the data controller is
The controller is [ • ], registered at [ • ](“salestone”, “we”).
For anything concerning personal data, write to [ • ]. We respond within the period required by the GDPR, and no later than one month from receiving a request.
2. Two distinct roles: controller and processor
This distinction is the most important part of this document, because it determines who is answerable for which data.
- We are the controller
- for data about people who create an account and use the platform (sign-in details, billing data, correspondence with us) and about people who contact us through the website form.
- We are a processor
- for content a customer company puts into the platform — in particular recordings and transcripts of sales conversations, and data about the people taking part in them. The controller of that data is our Customer; we process it only on their documented instructions, under the terms of the data processing agreement (DPA).
So if you took part in a sales conversation recorded by a salestone user, address any request about your data first to the company whose representative held the conversation. We forward every such request to the relevant Customer and help them act on it.
3. What data we process
- Account data — name, email address, team role, interface language, profile photo if one is added.
- Company data — name, industry, product and service descriptions, target audiences, competitors, training material added by the Customer.
- Recordings and transcripts — audio of practice conversations with the bot and of real conversations that a user deliberately uploaded or asked us to record, together with their transcript and speaker separation.
- Grading results and progress — conversation scores, development guidance, progress history, manager comments, coaching assistant conversations.
- Billing data — plan, seat count, payment history. We never see or store card details; Stripe handles them.
- Technical data — server logs, IP address, browser information, error events. Used solely for security and diagnostics.
4. Purposes and legal bases
- Providing the service
- Art. 6(1)(b) GDPR — performance of the service contract (account, bot practice, conversation grading, reporting).
- Billing and accounting
- Art. 6(1)(c) GDPR — legal obligation under tax and accounting law.
- Security and diagnostics
- Art. 6(1)(f) GDPR — our legitimate interest in keeping the service stable and secure.
- Communication and support
- Art. 6(1)(f) GDPR — legitimate interest in answering messages sent to us.
- Weekly email digests
- Art. 6(1)(f) GDPR — legitimate interest; every user can switch them off in account settings at any time.
5. Processing using artificial intelligence
The core of salestone is conversation analysis by language models. A conversation transcript and the company profile are sent to the providers listed in section 7, which generate a score and development guidance. Two things should be explicit:
- We do not train models on your data and we do not permit our providers to. Data is processed solely to generate a response to a specific request.
- An AI score is not a decision. It is training material and guidance for a manager, not an automated decision producing legal effects within the meaning of Art. 22 GDPR. We do not carry out profiling that automatically determines employment, pay or promotion. How a Customer uses a score remains their responsibility.
6. Recording conversations and consent
The platform supports three ways of working with a conversation: practice with an AI bot, uploading a recording of a real conversation, and recording an online meeting via a bot that joins the call.
For the latter two, obtaining the other party’s consent and informing them that the conversation is being recorded is the Customer’s obligation and that of the person holding the conversation. salestone provides the tool; we are not a party to the recorded conversation and we do not verify that consent was obtained. The Customer commits to this in the Terms of Service.
7. Who we entrust data to
We use only the providers we genuinely need to deliver the service. The list below is complete and we update it on every change:
| Provider | Purpose | Data scope | Location |
|---|---|---|---|
| Supabase | Database, authentication, audio file storage | All account data, recordings, transcripts, grading results | European Union (Ireland) |
| Vercel | Application hosting | Data in transit, server logs | European Union (Dublin) |
| AssemblyAI | Transcription and speaker diarization of recordings | Audio recordings | United States |
| Anthropic | Conversation grading, rep-speaker detection, manager copilot, industry trends | Transcripts, company profile, aggregated team results | United States |
| Google (Gemini) | Voice conversation with the practice bot, coaching chat, persona and scenario generation | Practice-conversation voice and transcript, company profile, chat messages | European Union / United States |
| OpenAI | Company website analysis during onboarding, coach cover imagery | Public company website content, training material descriptions | United States |
| Recall.ai | Joining and recording online meetings at the user's instruction | Online meeting audio, meeting metadata | United States |
| Resend | Transactional email delivery | Email address, name, notification content | United States |
| Stripe | Payment and subscription processing | Billing data, email address (Stripe is a separate controller of payment data) | European Union / United States |
Beyond these, data may be disclosed to authorities entitled to it by law. We do not sell data and do not share it with third parties for marketing.
8. Transfers outside the EEA
Some providers listed in section 7 process data in the United States. Transfers rely on Standard Contractual Clauses approved by the European Commission (Art. 46(2)(c) GDPR) and, where applicable, on the provider’s Data Privacy Framework participation. The database, audio files and application hosting stay within the European Union.
9. How long we keep data
- Audio recordings
- 90 days after grading completes. The file is then deleted; the transcript and score remain.
- Transcripts and grading results
- 24 months — the product's value is the progress trend over time, so history has to outlive a single conversation.
- Account and company data
- 30 days after the subscription ends, then deleted. During that window a Customer can export their data or reactivate.
- Billing records
- 5 years — set by tax law and not shortened on request.
- Server logs and error events
- 12 months.
10. Your rights
You have the right to:
- access your data and receive a copy of it,
- rectify inaccurate or incomplete data,
- erasure (the right to be forgotten),
- restriction of processing,
- data portability to another controller,
- object to processing based on legitimate interest,
- lodge a complaint with the President of the Personal Data Protection Office in Poland (ul. Stawki 2, 00-193 Warsaw) or your local supervisory authority.
Send requests to [ • ]. If a request concerns data for which we are only a processor (section 2), we pass it to the Customer acting as controller and tell the sender that we have done so.
11. Security
- All traffic over TLS; data at rest encrypted by the infrastructure provider.
- Isolation between companies enforced at the database level (Row Level Security), not only in application code.
- Access to production data limited to those who need it and recorded in an administrative audit log.
- Audio files reachable only through signed URLs that expire after one hour.
13. Changes to this policy
We announce material changes by email or in-app at least 14 days in advance. The effective date of the current version is shown at the top of the document. The Polish version is binding; this English version is informational.