Privacy Policy
How we collect, use, and protect your information.
Last updated: September 2026
Controller: HeySali, a brand of Glatt Digital GmbH
Sunnhaldenstrasse 9a, 8192 Glattfelden, SWITZERLAND
E-mail: hello@heysali.ch
Website: heysali.ch
HeySali is a brand of Glatt Digital GmbH. In this Privacy Policy, Glatt Digital GmbH (hereinafter the "Company", "we" or "us") informs you about the collection and processing of personal data when you visit our website (heysali.ch), use our Software-as-a-Service (SaaS) solution HeySali or otherwise have business dealings with us.
1. Legal Framework and Compliance
The Company processes personal data in strict compliance with the Swiss Federal Act on Data Protection (FADP) and, where applicable, the General Data Protection Regulation of the European Union (GDPR). References to a legal basis in this policy mean Art. 6(1) GDPR: contract (point b) for everything the Service requires, consent (point a) for cookies and communications, legitimate interest (point f) for operation, security and our customers' B2B sales purposes.
2. Collection and Processing of Personal Data
2.1 Data Provided Directly by the User
We collect personal data that you expressly provide to us when registering an account, subscribing to our services or submitting support requests. This includes in particular, but is not limited to: name, telephone number, e-mail address and company details. What we store in each case is set out in Sections 7 to 9.
2.2 Data Obtained from Specialised Third-Party Providers (Sales Intelligence)
To provide our services in the areas of "Sales Intelligence" and "Lead Generation" within the HeySali platform, we use data from professional third-party providers of B2B contact data and of company and contact data enrichment. For the search queries we send them, they act as our sub-processors; for the data from their own databases, they are controllers in their own right.
Restrictions on Use: In accordance with our contractual obligations towards these providers, the data provided may be used exclusively for lawful B2B sales and marketing purposes. Use for the following purposes is strictly prohibited:
• Assessments of creditworthiness (compliance with the Fair Credit Reporting Act – FCRA).
• Decisions regarding employment, insurance claims or government benefits.
• The creation of independent databases through systematic caching or scraping beyond the agreed scope of services.
• The systematic export of data in excessive volumes ("bulk exports").
Disclaimer of Warranty and Liability: Neither Glatt Digital GmbH nor our third-party providers give any warranty or accept any liability towards end users for the accuracy, completeness or availability of the data provided.
Expiry of Data Rights: All licences to use the data provided by our third-party partners are strictly tied to an active subscription. Upon termination of your contract with HeySali, your right to use such data expires immediately, and all data records must be deleted in accordance with Section 11.
2.3 Data Obtained from Public Registers (Commercial Register / Zefix, simap)
To provide business signals (e.g. company changes, capital increases or changes of address), HeySali systematically collects and processes publicly available data from the Central Business Name Index (Zefix) of the Federal Commercial Registry Office (FCRO / EHRA), including the notices of the Swiss Official Gazette of Commerce (SOGC / SHAB) available through it, as well as from the procurement platform simap.ch and further open sources (Section 9). To the extent that such data allows conclusions to be drawn about natural persons (e.g. shareholders, managing directors or sole proprietors), it is processed exclusively for the lawful B2B sales and marketing purposes of our customers. Legal basis: legitimate interest (Art. 6(1)(f) GDPR); the data comes from publicly accessible sources.
2.4 Persons Whose Business Contact Details the Platform Contains
The platform may contain business details about you even if you have never been in contact with us: name, job title, employer, business e-mail address and telephone number, LinkedIn profile and public events concerning your company. The sources are the data providers under Section 2.2, the public registers and sources under Section 2.3, and public company websites and posts. We make this data available to our customers for their B2B sales; the legal basis is legitimate interest (Art. 6(1)(f) GDPR). Once a customer unlocks your data, that customer is responsible for any further use and for any contact made. Your rights, in particular access and objection: Section 12.
3. Purpose of Data Processing
Glatt Digital GmbH processes your data to provide the HeySali platform, to perform the contract, to analyse website usage and to optimise marketing and sales processes (CRM), in accordance with our corporate purpose as registered in the Swiss Commercial Register.
4. Data Disclosure and International Transfers
We disclose data to the service providers and data providers named in Section 10, to the extent necessary for the purpose stated there, to authorities where we are legally obliged to do so, and, for Platform Data that a customer unlocks, to that customer.
Reports to data providers. As required by our contracts, we report to our data providers the use of their data per customer company (company size, country of registered office, industry, services used, credits consumed), in aggregated form and without personal data of users; for support and billing matters, also the customer company's contact person.
5. Data Security
We protect your data with technical and organisational measures appropriate to the risk: encrypted transmission, access only with a personal account, separation of customer data by workspace and logging of administrative access.
6. The Website heysali.ch
Visiting the website. When you visit heysali.ch, your browser transmits your IP address, date and time, the page requested, browser and operating system. heysali.ch, www.heysali.ch and app.heysali.ch are delivered through the Cloudflare network, which acts as a proxy in front of our servers in Switzerland; in doing so, Cloudflare sees your IP address and may set a technical cookie to protect against automated access. Calls from the app to our API go directly to Switzerland. Based on the country that Cloudflare assigns to your IP address, we redirect visitors from Switzerland, Liechtenstein, Germany and Austria to the German version and show prices in CHF or USD; we do not store the country. Legal basis: legitimate interest in secure operation (Art. 6(1)(f) GDPR).
Without your consent we set only what operation requires: the cookie NEXT_LOCALE (1 year) for your language choice; your decision in the cookie banner together with its time in your browser's local storage (heysali.cookie-consent, not transmitted to us); Cloudflare Turnstile on the contact form and the booking form, which loads only with the form, transmits technical details of your browser to Cloudflare and may create its own storage under challenges.cloudflare.com (token valid for five minutes). We serve fonts ourselves; there is no connection to Google Fonts.
Cookie banner. Until you have decided, the website loads no analytics, marketing or chat script (Google Consent Mode v2, all storage types "denied"). You allow each category individually and can change your choice at any time via the cookie icon "Cookie Preferences" at the bottom left of the page; on withdrawal we instruct HubSpot to remove its cookies and end the chat. Legal basis: consent (Art. 6(1)(a) GDPR).
Category — Service and provider — Purpose — Cookies and storage
Essential — Language cookie, consent record, Cloudflare Turnstile — Language, record of your choice, protection against bots — NEXT_LOCALE; heysali.cookie-consent (local storage); Turnstile token
Analytics and advertising (Google) — Google Tag Manager loads the Google tag of Google Ads, which also sends data to Google Analytics 4; Google Ireland Ltd (Dublin) and Google LLC (USA) — Usage statistics; measuring whether ads lead to registrations and bookings; remarketing. Google receives your IP address; the data is not anonymous — _ga, _ga_*, _gid, _gat, _gcl_*
Marketing — HubSpot tracking code (EU data centre); HubSpot, Inc. (USA) — Recognising you and linking your page views to your contact record once you fill in a form or book a call — hubspotutk, __hstc, __hssc, __hssrc
Functional — Live chat by tawk.to Inc. (USA) — Chat with us; the chat transcript and any details you volunteer, such as name and e-mail, go to tawk.to — TawkConnectionTime, twk_*, Tawk_*, __tawkuuid
Blog. Our blog (blog.heysali.ch) is hosted by HubSpot; HubSpot's privacy notice applies there. On heysali.ch we display posts from the feed without your browser contacting HubSpot.
7. Booking a Call ("Book a demo")
When you book a call, we collect first name, last name, business e-mail address (personal providers such as Gmail are rejected), company, job title, telephone number, time and duration, language and time zone; the form is protected by Turnstile. The booking runs through our API in Switzerland into HubSpot's meeting calendar (EU data centre): HubSpot creates you as a contact, enters the appointment and sends you the invitation with a Google Meet link. We do not store the booking in our database; our API keeps short-lived caches and one log entry with the HubSpot contact ID and your consent answers.
The form shows the consent texts of the HubSpot meeting. Consent to further communications is voluntary and not required for the booking; you can withdraw it via the unsubscribe link or by e-mail to hello@heysali.ch. Legal basis: pre-contractual measure (Art. 6(1)(b) GDPR); communications only with consent (point a).
8. Contact Form and E-mails
Contact form. We store first name, last name, company, e-mail address, telephone number and message together with your IP address and browser identifier in our database in Switzerland (form protected by Turnstile), receive a notification by e-mail and reply by e-mail. The same applies to e-mails to hello@heysali.ch or support@heysali.ch. Legal basis: answering your enquiry (Art. 6(1)(b) and (f) GDPR).
System e-mails. Address verification, password resets, invitations to a workspace, the notice of your integration request to our support team (with your address as the reply-to address) and the contact-form notification are sent through Mailgun (Mailgun Technologies, Inc., Sinch group, USA) in its EU region (api.eu.mailgun.net), sender mailer.heysali.ch. For each message we log type, recipient, subject and delivery status.
Weekly digest. Every week, active members of a workspace with read access to lists receive an e-mail with companies from their leads and the reason why now. You can switch the digest off in your profile. Legal basis: contract (point b), with the option to object.
9. Using the App (app.heysali.ch)
Account and login. On registration we collect first name, last name, business e-mail address (personal providers are rejected), password (stored as a hash only) and language. You confirm your address with a code that we send by e-mail; registration, login and password reset are protected by Turnstile. On each login we store the time, IP address and browser identifier. Your session is a token (JWT, valid for 7 days) in your browser's local storage; the cookie heysali_ui_locale (1 year) remembers the language. Legal basis: contract (point b); the login record based on our legitimate interest in security (point f).
Profile and team. You may add a telephone number, job title, short bio, time zone, date format and a profile photo. The profile photo is stored in our object storage in Switzerland at a fixed address that anyone who knows it can open without logging in. If you invite colleagues, we send an invitation link (valid for 7 days) to the e-mail address you enter; the legal basis for this is your company's legitimate interest in working together (point f).
Customer Data in the workspace. Companies, contacts, deals, activities, comments with attachments, imports, lead lists, target profiles and uploaded briefs belong to you. You are the controller for them; we process them as your processor on your instructions and under Section 9 of the GTC, stored on a server in Switzerland.
Searches with data providers. When you search for contacts or companies, we send your criteria (job functions, departments, countries, company names or domains, technologies; for a targeted search also a person's name, company or LinkedIn address) to our data providers. They return name, job title, company, e-mail address, telephone number and LinkedIn profile, or company data, company events, intent topics and the company's public LinkedIn posts. You are responsible for your outreach.
Target profiles and public sources. For your target profiles we search public information daily, using a recognisable identifier. This may include names and roles of officers, authorised signatories, contact persons and employees as published there. We store hits as signals (Section 11). Legal basis: legitimate interest (point f), publicly accessible sources.
AI features. For certain features we use language models operated in Switzerland. The model receives: your free-text search query when we derive search filters from it; excerpts from Commercial Register notices (up to 650 characters) with company name, purpose and category; excerpts from company websites and their changes; texts of public LinkedIn posts; excerpts from briefs you upload. Your CRM contact records do not go to the model. We log inputs and outputs for 180 days. Training of the models with your inputs is excluded.
Payments. Before you purchase a subscription, we collect company name, UID/VAT number and address. We pass the amount, currency, plan, number of users and workspace reference to Payrexx AG (Thun). You enter payment details exclusively with Payrexx; we receive payment confirmations and store them together with the IP address of the sending system (no deletion period). Legal basis: contract (point b) and statutory retention duty (point c).
YouTube. YouTube videos are embedded in the app settings; when you open that page, your browser loads the player from youtube.com (Google), and Google may set cookies.
10. Recipients and Transfers Abroad
Personal data is received, to the extent the respective purpose requires, by: our hosting and AI provider, which processes data in Switzerland; our service providers for website delivery and bot protection, for system e-mails, website analytics, call booking and live chat (USA, partly EU; transfers based on the Swiss-U.S. and EU-U.S. Data Privacy Framework or on Standard Contractual Clauses); our payment service provider in Switzerland; our data providers for B2B contact and company data in EU and United Kingdom in anonymous form (countries covered by an adequacy decision of the Swiss Federal Council); authorities, where we are legally obliged to do so. Platform Data that a customer unlocks is received by that customer in the country of its registered office. Switzerland, the EEA, the United Kingdom and Canada are considered countries with adequate data protection; to other countries, in particular the USA, we transfer data only with Standard Contractual Clauses. The customer is itself responsible for its use.
11. Retention and Deletion
We keep personal data for as long as the purpose or a statutory duty requires. The following periods apply today:
Data — Period
Account and workspace data — For the term of the contract. Today, the workspace is archived after the contract ends and permanently deleted at your request. Once automatic deletion is in place, we will delete account and workspace data 30 days after the contract ends.
Verification and reset codes; invitation links; sessions — 15 minutes; 7 days; 7 days
Contact form — until the enquiry has been dealt with; there is no automatic deletion period today
Call booking — with us only the log entry (Section 7); the contact in HubSpot until you request deletion
Signals from target profiles (Section 9) — 365 days
Invoices and payment records — 10 years (Art. 958f of the Swiss Code of Obligations (CO))
Third-party data that you have unlocked may not be used further after the contract ends (Section 2.2); it is deleted together with the workspace. Cookies and browser storage: Section 6.
12. Your Rights
Under the FADP and the GDPR you have the right to access your personal data, to rectification, erasure and restriction of processing, to receive your data in a common electronic format (data portability), to object to processing based on legitimate interest and to withdraw consent with effect for the future. Write to hello@heysali.ch or to the address above; we may request proof of identity and usually reply within 30 days. If your request concerns data that a customer holds about you in its workspace, we forward it to that customer as the controller.
You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC, Feldeggweg 1, 3003 Bern, edoeb.admin.ch); in the EU, with the supervisory authority at your place of residence.
13. Changes
We amend this policy when our services or the law change. The version published on heysali.ch with the month stated above is authoritative. On registration we record which version you accepted; we inform registered users of material changes in the app or by e-mail.