Legal

Privacy Policy

What data salestone collects, why, on what legal basis, who we entrust it to, and how long we keep it. This covers the platform at salestone.eu and the marketing site.

Effective 31 August 2026 · version 1.0

Draft pending legal review. Company registration details are not filled in yet, so this document is not yet binding.

1. Who the data controller is

The controller is [ • ], registered at [ • ](“salestone”, “we”).

For anything concerning personal data, write to [ • ]. We respond within the period required by the GDPR, and no later than one month from receiving a request.

2. Two distinct roles: controller and processor

This distinction is the most important part of this document, because it determines who is answerable for which data.

We are the controller
for data about people who create an account and use the platform (sign-in details, billing data, correspondence with us) and about people who contact us through the website form.
We are a processor
for content a customer company puts into the platform — in particular recordings and transcripts of sales conversations, and data about the people taking part in them. The controller of that data is our Customer; we process it only on their documented instructions, under the terms of the data processing agreement (DPA).

So if you took part in a sales conversation recorded by a salestone user, address any request about your data first to the company whose representative held the conversation. We forward every such request to the relevant Customer and help them act on it.

3. What data we process

  • Account data — name, email address, team role, interface language, profile photo if one is added.
  • Company data — name, industry, product and service descriptions, target audiences, competitors, training material added by the Customer.
  • Recordings and transcripts — audio of practice conversations with the bot and of real conversations that a user deliberately uploaded or asked us to record, together with their transcript and speaker separation.
  • Grading results and progress — conversation scores, development guidance, progress history, manager comments, coaching assistant conversations.
  • Billing data — plan, seat count, payment history. We never see or store card details; Stripe handles them.
  • Technical data — server logs, IP address, browser information, error events. Used solely for security and diagnostics.

4. Purposes and legal bases

Providing the service
Art. 6(1)(b) GDPR — performance of the service contract (account, bot practice, conversation grading, reporting).
Billing and accounting
Art. 6(1)(c) GDPR — legal obligation under tax and accounting law.
Security and diagnostics
Art. 6(1)(f) GDPR — our legitimate interest in keeping the service stable and secure.
Communication and support
Art. 6(1)(f) GDPR — legitimate interest in answering messages sent to us.
Weekly email digests
Art. 6(1)(f) GDPR — legitimate interest; every user can switch them off in account settings at any time.

5. Processing using artificial intelligence

The core of salestone is conversation analysis by language models. A conversation transcript and the company profile are sent to the providers listed in section 7, which generate a score and development guidance. Two things should be explicit:

  • We do not train models on your data and we do not permit our providers to. Data is processed solely to generate a response to a specific request.
  • An AI score is not a decision. It is training material and guidance for a manager, not an automated decision producing legal effects within the meaning of Art. 22 GDPR. We do not carry out profiling that automatically determines employment, pay or promotion. How a Customer uses a score remains their responsibility.

6. Recording conversations and consent

The platform supports three ways of working with a conversation: practice with an AI bot, uploading a recording of a real conversation, and recording an online meeting via a bot that joins the call.

For the latter two, obtaining the other party’s consent and informing them that the conversation is being recorded is the Customer’s obligation and that of the person holding the conversation. salestone provides the tool; we are not a party to the recorded conversation and we do not verify that consent was obtained. The Customer commits to this in the Terms of Service.

7. Who we entrust data to

We use only the providers we genuinely need to deliver the service. The list below is complete and we update it on every change:

ProviderPurposeData scopeLocation
SupabaseDatabase, authentication, audio file storageAll account data, recordings, transcripts, grading resultsEuropean Union (Ireland)
VercelApplication hostingData in transit, server logsEuropean Union (Dublin)
AssemblyAITranscription and speaker diarization of recordingsAudio recordingsUnited States
AnthropicConversation grading, rep-speaker detection, manager copilot, industry trendsTranscripts, company profile, aggregated team resultsUnited States
Google (Gemini)Voice conversation with the practice bot, coaching chat, persona and scenario generationPractice-conversation voice and transcript, company profile, chat messagesEuropean Union / United States
OpenAICompany website analysis during onboarding, coach cover imageryPublic company website content, training material descriptionsUnited States
Recall.aiJoining and recording online meetings at the user's instructionOnline meeting audio, meeting metadataUnited States
ResendTransactional email deliveryEmail address, name, notification contentUnited States
StripePayment and subscription processingBilling data, email address (Stripe is a separate controller of payment data)European Union / United States

Beyond these, data may be disclosed to authorities entitled to it by law. We do not sell data and do not share it with third parties for marketing.

8. Transfers outside the EEA

Some providers listed in section 7 process data in the United States. Transfers rely on Standard Contractual Clauses approved by the European Commission (Art. 46(2)(c) GDPR) and, where applicable, on the provider’s Data Privacy Framework participation. The database, audio files and application hosting stay within the European Union.

9. How long we keep data

Audio recordings
90 days after grading completes. The file is then deleted; the transcript and score remain.
Transcripts and grading results
24 months — the product's value is the progress trend over time, so history has to outlive a single conversation.
Account and company data
30 days after the subscription ends, then deleted. During that window a Customer can export their data or reactivate.
Billing records
5 years — set by tax law and not shortened on request.
Server logs and error events
12 months.

10. Your rights

You have the right to:

  • access your data and receive a copy of it,
  • rectify inaccurate or incomplete data,
  • erasure (the right to be forgotten),
  • restriction of processing,
  • data portability to another controller,
  • object to processing based on legitimate interest,
  • lodge a complaint with the President of the Personal Data Protection Office in Poland (ul. Stawki 2, 00-193 Warsaw) or your local supervisory authority.

Send requests to [ • ]. If a request concerns data for which we are only a processor (section 2), we pass it to the Customer acting as controller and tell the sender that we have done so.

11. Security

  • All traffic over TLS; data at rest encrypted by the infrastructure provider.
  • Isolation between companies enforced at the database level (Row Level Security), not only in application code.
  • Access to production data limited to those who need it and recorded in an administrative audit log.
  • Audio files reachable only through signed URLs that expire after one hour.

12. Cookies

We use strictly necessary cookies only — the ones without which the service does not work: the authentication session cookie, the interface language cookie, and a cookie marking the active company for accounts belonging to more than one organisation.

We use no analytics, advertising or cross-site tracking cookies, which is why you see no consent banner — there is no consent for us to ask for.

13. Changes to this policy

We announce material changes by email or in-app at least 14 days in advance. The effective date of the current version is shown at the top of the document. The Polish version is binding; this English version is informational.

The Polish version of this document is the binding one. The English version is provided for information.