Privacy Policy
1. Introduction
Saldi ("we", "us", or "our") is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, and share your personal data when you visit our website or use our services. We comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
The data controller is Saldi Tech BV, Weesperstraat 61, 1018 VN Amsterdam, the Netherlands.
2. Information we collect
From visitors to this website
- Contact form data: first name, last name, work email address, company name, and company size, together with the page the form was submitted from.
- Technical information: IP address, browser type, device information, and usage data.
- Cookie data: where you have consented, identifiers that link your visit to a marketing campaign. See our Cookies Notice.
- Interaction data: where you have consented, a recording of how you used our pages — clicks, scrolling, mouse movement and the order of pages viewed — captured by Microsoft Clarity. Text entered into forms is masked. See section 7.
From customers and prospective customers
- Business information: company name, address, registration number, contact details of authorised representatives.
- Banking information: bank account details (IBAN, account holder name), transaction data (date, amount, recipient, description).
- Financial information: data related to your business financial accounts for reconciliation purposes.
Sensitive data
We do not collect special categories of personal data, such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, or data concerning a person's sex life or sexual orientation.
3. How we use your information
- Providing services: to facilitate banking payments, provide access to transaction data, and assist in reconciliation with your business financial accounts.
- Responding to enquiries: to reply to messages submitted through our contact form.
- Improving services: to analyse usage patterns, troubleshoot issues, and develop new features. Where you have consented, this includes reviewing recordings of how our website is used, as described in section 7.
- Marketing and campaign measurement: where you have consented, to understand which marketing campaigns bring visitors to our website. See section 6.
- Communication: to send service-related notifications, updates, and, with your consent, marketing communications.
- Legal compliance: to comply with applicable laws and regulations, including AML/CFT obligations.
4. Legal basis for processing
- Contractual necessity: processing necessary to perform a contract with you, or to take steps at your request before entering into one.
- Legitimate interests: processing necessary for our legitimate interests, such as responding to enquiries, improving our services, preventing fraud, and ensuring security, where those interests do not override your fundamental rights and freedoms.
- Consent: for marketing communications and for all non-essential cookies and similar technologies, including the campaign tracking described in section 6 and the session analytics described in section 7. You may withdraw consent at any time.
- Legal obligation: where processing is required by law.
5. Sharing your information
We may share your personal data with the following categories of recipient:
- Netlify — hosts this website and receives and stores contact form submissions on our behalf.
- Payment processors and open banking providers — to facilitate banking payments and retrieve transaction data.
- Service providers — third parties who assist us in providing our services, such as cloud hosting and IT support.
- Legal and regulatory authorities — where required by law or to protect our legal rights.
We do not sell your personal data.
Appointed data processors
We engage carefully selected third-party partners and service providers who process personal data on our behalf in compliance with the GDPR. From time to time, we appoint digital marketing agencies to conduct outreach and marketing activities on our behalf. As part of these activities, personal data may be processed in accordance with applicable data protection laws.
Our appointed data processors include:
- Prospect Global Ltd (trading as Sopro), registered in the United Kingdom, company number 09648733. Sopro is registered with the Information Commissioner's Office under reference ZA346877. You can contact Sopro and view their privacy policy at sopro.io. Their Data Protection Officer can be reached at dpo@sopro.io.
- Netlify, which hosts this website and receives contact form submissions on our behalf.
Each processor acts only on our documented instructions under a written data processing agreement, as required by Article 28 of the GDPR.
Microsoft is not in this list. We use Microsoft Clarity for website analytics, but Microsoft states that it operates Clarity as a controller in its own right rather than as our processor. Section 7 explains what that means for you.
6. Website campaign measurement (Sopro)
Where you consent to analytics and marketing cookies, we use a website plugin provided by Sopro. This plugin allows us to understand which of our outbound marketing campaigns led you to visit our website.
When you arrive from one of our campaign emails, the link may contain a unique identifier. The plugin stores that identifier in a cookie on your device and sends the page address you are visiting and the page you arrived from to Sopro's servers. This means that a visit to our website can be linked to you as an identified recipient of one of our emails, and to the pages you view on subsequent visits.
This processing takes place only with your consent. If you decline, the plugin is not loaded and no such cookies are set. You may withdraw your consent at any time using the Cookie settings link in the footer of any page, and you have the right to object to this processing at any time under Article 21 GDPR.
Sopro acts as our data processor for this activity: it processes the data only on our instructions, under a written data processing agreement. Saldi Tech BV remains the data controller. The cookies involved, and how long each lasts, are set out in our Cookies Notice. Sopro is established in the United Kingdom; see section 10.
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you.
7. Website session analytics (Microsoft Clarity)
Where you consent to analytics cookies, we use Microsoft Clarity to understand how this website is actually used. Clarity records your interactions with our pages — clicks, scrolling, mouse movement, the sequence of pages you view, your browser and device type, and an approximate location derived from your IP address — and lets us replay those sessions and view them as aggregate heatmaps and usage statistics. We use this to find parts of the site that confuse people, and to fix them.
Clarity masks text typed into form fields and the contents of dropdowns before a recording leaves your browser, so the name, email address and company you enter in our demo request form do not appear in a replay. We do not attempt to identify you from a recording, and we do not combine recordings with the information you send us through the form.
This processing takes place only with your consent. If you decline, the Clarity script is never loaded, no recording is made and no Clarity cookie is set. You may withdraw your consent at any time using the Cookie settings link in the footer of any page, and you have the right to object to this processing at any time under Article 21 GDPR.
Microsoft's role
This differs from our arrangement with Sopro and is worth stating plainly. Microsoft does not act as our processor for Clarity. Microsoft states that it operates Clarity as a data controller in its own right, and it uses data collected through Clarity for its own purposes alongside providing the service to us. Some of the cookies Clarity sets — in particular MUID — are Microsoft identifiers that recognise your browser across Microsoft sites and services, and Microsoft uses them for advertising and analytics of its own. We receive no advertising data or revenue from this.
What that means in practice is that when you accept analytics cookies you are consenting to two separate things: our use of Clarity's reports about our own website, and Microsoft's own processing as a controller, which is governed by Microsoft's privacy statement rather than by this policy. Rights you wish to exercise against Microsoft in respect of that processing should be directed to Microsoft; we will help where we can. In the EEA the Clarity contracting entity is Microsoft Ireland Operations Limited; see section 10 on transfers.
Clarity retains session recordings for 30 days, except for recordings we mark as favourites and a sample retained by Microsoft, which are kept for up to 9 months. Heatmap and aggregate data is available for up to 9 months. The cookies involved, and how long each lasts, are set out in our Cookies Notice.
8. Data retention
- Contact form submissions: retained for up to 24 months from the last contact, unless a business relationship begins, in which case customer retention applies.
- Cookie identifiers: for the periods set out in the Cookies Notice, the longest being 13 months.
- Session recordings: 30 days, except recordings marked as favourites and a sample retained by Microsoft, which are kept for up to 9 months. Heatmap and aggregate data is available for up to 9 months.
- Customer and transaction data: retained for the duration of the contract and afterwards for as long as required by law, including statutory accounting and AML/CFT retention obligations.
Where a longer retention period is required or permitted by law, we retain data for that period.
9. Your rights
Under the GDPR you have the right to access your personal data, to have inaccurate data corrected, to have data erased, to restrict processing, to data portability, to object to processing (including profiling and direct marketing), and to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, contact us using the details in section 13. We will respond within one month.
Right to complain. If you believe we have not handled your personal data properly, you have the right to lodge a complaint with a supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). You may also complain to the authority in your country of residence or workplace.
10. International data transfers
Sopro is established in the United Kingdom. The European Commission has adopted an adequacy decision for the United Kingdom, which permits transfers of personal data there without additional safeguards.
Microsoft Clarity data is stored in Microsoft's Azure cloud. In the EEA the contracting entity is Microsoft Ireland Operations Limited, which relies on the European Commission's Standard Contractual Clauses for transfers to Microsoft Corporation in the United States.
Where we transfer personal data outside the European Economic Area to a country without an adequacy decision, we put appropriate safeguards in place, such as the European Commission's Standard Contractual Clauses. You may request a copy of the relevant safeguards using the contact details below.
11. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and revising the date at the top of this page.
13. Contact us
If you have questions about this Privacy Policy or our data practices, contact us at:
Saldi Tech BV
Weesperstraat 61, 1018 VN Amsterdam, the Netherlands
policy@saldi.tech