1. Controller and scope
Saem Group s. r. o., Púpavová ulica 4139/37, 900 25 Chorvátsky Grob, Slovakia, IČO 57 600 171, registered in the Commercial Register maintained by Mestský súd Bratislava III (Municipal Court Bratislava III), Section Sro, entry 199008/B (“Dotless”, “we”, “us”, or “our”) is the controller for the personal data described in this Privacy Policy. Contact us at support@dotless.co or +421 949 086 278.
This Policy covers dotless.co, our application, account and checkout flows, business discovery and enrichment, outreach, websites made with Dotless, support, and related interactions. The Service is for business and professional use, but this Policy protects every individual whose data we process, including users, administrators, prospects, website visitors, recipients, and business contacts.
When Dotless processes personal data contained in Customer Content solely on a business customer’s documented instructions, that customer is normally the controller and Dotless is its processor under our Data Processing Addendum. Dotless remains an independent controller for account, billing, security, product telemetry, its own business-contact index, legal-compliance, and direct-relationship data described here. The customer’s privacy notice governs its own outreach and websites.
2. Data we collect and where it comes from
- Account and identity: name, business email, authentication identifiers, password hash where password login is used, profile image or identity data returned by a connected sign-in provider, organization, role, workspace membership, account settings, and support communications. We receive this from you, your administrator, or sign-in provider.
- Contract and legal-acceptance evidence: legal bundle and document version and content hashes; the exact acceptance wording; the business-use, contractual-capacity, authority, agreement, and acknowledgement represented by an account-creation, agreement-review, or checkout action; server-recorded timestamp and acceptance source; identity provider; a pseudonymous account and email reference; Stripe Checkout Session and event identifiers where applicable; acceptance UI version; and limited user-agent, language, and request context. We generate this record when you take an acceptance action and receive relevant authentication or checkout identifiers from the connected provider. The acceptance record described here does not include an IP address.
- Business and sender profile: company details, sender identity, business address, default country, language, phone settings, signatures, preferences, and compliance settings, supplied by you or your administrator.
- Billing and transaction: billing contact, plan, coupon, subscription, invoice, tax status, payment status, and provider identifiers. Stripe receives payment-card details directly; Dotless does not store full payment-card numbers.
- Connected-service data: connected email address and provider, SMTP host, port, username, encryption setting, OAuth tokens or scopes where enabled, domain and deployment configuration, secure references to secrets, and integration events. We receive this from you and connected providers.
- Customer Content and websites: uploaded lists, files, brand assets, instructions, templates, drafts, messages, generated output, website projects, code, pages, images, forms, domains, and publication settings.
- Prospect and public-business data: business names and categories, business and professional contact details, address and region, websites, social links, public profile data, ratings and review counts, place or source identifiers, search criteria, verification status, and source metadata. Sources can include public business websites, public registers and directories, search and map services, licensed data, Customer input, and third-party search, collection, validation, and enrichment providers. See our Prospect Data Notice.
- Outreach and suppression: recipient details, legal-basis or source notes supplied by Customer, templates, subjects, message bodies, sequence steps, timestamps, provider message IDs, status, bounce, complaint, objection, and unsubscribe records.
- Usage, device, and security: IP address, approximate location derived from IP, date and time, pages and features used, searches, map interactions, plan limits, event and performance data, referrer, browser, operating system, device identifiers supplied by providers, session, logs, error and abuse signals.
- Marketing: email, name if provided, source and time of the request, consent or objection record, campaign engagement where enabled, and communications preferences.
- Storage technologies: session cookies, local storage, OAuth and recovery state, security tokens, preferences, popup confirmation, and analytics or map-service storage described in the Cookie and Storage Notice.
Please do not submit special-category data, highly sensitive identifiers, private personal accounts, or children’s data. If Customer chooses to submit such data, Customer must first have a lawful basis, satisfy additional legal requirements, and obtain Dotless’s written approval where the Terms require it.
2A. Google user data and the Gmail send-only connection
This section applies specifically to information Dotless receives from Google APIs and controls over any broader or more general description elsewhere in this Policy if there is a conflict. Dotless’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
If you choose to connect Gmail, Dotless requests only basic Google account identity information (including the verified email address and related OAuth identifiers and scopes) and the Gmail permission needed to send email on your behalf. Dotless also processes the OAuth access and refresh tokens, the outbound message content you direct Dotless to send, and limited request, delivery, connection-status, security, and troubleshooting metadata needed to provide the connection. Dotless does not request a Gmail read scope and does not use the connection to read or retrieve your inbox, sent mailbox, replies, contacts, calendar, or Google Drive files.
We use this Google user data only to identify the connected sender, establish and maintain the connection, transmit the messages you direct, display connection and send status, protect the connection, provide support, diagnose delivery or connection errors, and improve that visible, user-facing Gmail connection. Google Workspace API data, including raw data and data aggregated, anonymized, or derived from it, is not used, transferred, or sold for advertising, marketing profiles, public-business discovery, prospect enrichment, credit or lending decisions, creating or selling databases, or developing, improving, or training generalized, shared, or non-personalized artificial intelligence or machine-learning models. Google Workspace APIs are not used to develop, improve, or train non-personalized AI and/or ML models. These prohibited uses cannot be enabled by Customer consent, configuration, or instruction. Google user data is excluded from section 4, is not combined with our prospect index, and is not sent to generative-AI, search, enrichment, or advertising providers.
We transfer Google user data only to Google as necessary to carry out the send request and to infrastructure or security subprocessors that process the minimum data needed to operate and protect the connection on our behalf. We do not sell Google user data, disclose it to data brokers, use it for personalized or cross-context advertising, or allow a third party to use it for its own unrelated purposes. Human access is prohibited except when you give explicit permission for a specific support matter, when it is necessary to investigate abuse or a security incident, or when access is required by applicable law. Any permitted access is limited to authorized personnel and subject to access controls and confidentiality duties. Our employees, agents, contractors, and successors must comply with the Google API Services User Data Policy, including its Limited Use requirements.
OAuth credentials are stored in access-controlled server-side systems and retained only until you disconnect Gmail, delete the account, or replace the credential, subject to the limited encrypted-backup cycle in section 8. Disconnecting Gmail removes Dotless’s stored connection and revokes or invalidates the credential where the provider supports that action. Messages already sent remain in Google’s systems under your Google account and Google’s terms; Dotless does not read those messages back from Gmail.
3. Purposes and legal bases
Where the GDPR or similar law applies, we use the following purposes and legal bases:
- Provide contracted business services: create accounts, authenticate, manage workspaces, perform searches and enrichment, process projects, generate requested output, connect providers, send Customer-directed messages, publish websites, apply plan limits, and provide support. Basis: performance of our business contract or steps requested before it, and legitimate interests where the contracting party is an organization rather than the individual user.
- Contract formation and evidence: confirm business-use eligibility, form, prove, administer, and enforce the agreement, associate acceptance with the applicable legal bundle, manage required re-acceptance, and resolve contract questions or claims. Basis: contract and steps requested before entering it, legitimate interests in maintaining reliable agreement records and enforcing our rights, and legal obligations or the establishment, exercise, or defence of legal claims where applicable.
- Billing and administration: process payment, invoices, subscriptions, discounts, tax, and accounting. Basis: contract, legitimate interests in operating our business, and legal obligations.
- Security and integrity: prevent fraud, spam, misuse, credential compromise, and technical incidents; enforce terms; troubleshoot; maintain logs, backups, suppression records, and service reliability. Basis: legitimate interests in protecting users, recipients, Dotless, and providers, and legal obligations.
- Business discovery and data quality: identify and organise public business and professional-contact information, verify or enrich records, record sources, and respond to correction or objection requests. Basis: legitimate interests in enabling proportionate B2B discovery and accurate business records, balanced against the individual’s role, expectations, source, data sensitivity, and rights. We do not rely on this basis where local law requires consent or the individual’s interests override it.
- Customer-directed outreach: act on a Customer’s instructions to prepare and transmit communications and maintain account-level suppression. Basis: the Customer determines its own lawful basis as controller; Dotless processes under the DPA. Dotless uses minimal delivery and abuse data for its legitimate interests in operating a safe service.
- Product analytics and improvement: measure performance and feature use, diagnose errors, plan capacity, and improve usability using telemetry and, where practical, aggregated or de-identified data. Basis: legitimate interests, or consent where storage or analytics law requires it.
- Service communications: send security, billing, support, product-operation, and material legal notices. Basis: contract, legitimate interests, and legal obligations.
- Marketing: send offers and product updates. Basis: consent where required; otherwise legitimate interests for proportionate marketing to existing business relationships with a clear opt-out. You can unsubscribe at any time.
- Legal and corporate matters: comply with law and authority requests, establish or defend claims, conduct audits, obtain advice, and complete a financing, reorganization, or transaction. Basis: legal obligations and legitimate interests.
Where we rely on legitimate interests, you may ask for information about our balancing assessment. Where processing is based on consent, refusal has no unrelated consequence and withdrawal does not affect earlier lawful processing. Contract-required fields are identified in the Service; without them, we may be unable to create an account, process payment, connect a feature, or perform the request.
4. AI, search, enrichment, and automated processing
This section does not apply to information received from Google APIs. Section 2A exclusively governs that data, and no Customer setting, instruction, or consent can make Google user data available to the providers or model-training uses described in this section.
At your request, Dotless may send the minimum relevant input (such as business details, contact candidates, a template, website content, search settings, or instructions) to search, collection, validation, enrichment, image, code-sandbox, or generative-AI providers. Output can be wrong or non-unique and must be reviewed. Current providers and functions are listed in our Subprocessor Register; a provider may instead act as an independent recipient where it processes under its own terms at Customer’s direction.
Dotless does not use Customer Content to develop, improve, or train a general-purpose or shared generative-AI or machine-learning model. We do not make solely automated decisions based on personal data that produce legal or similarly significant effects about users or prospects. Customers must not use Dotless output for such decisions without a lawful process and meaningful human review.
5. Connected email, forms, and public websites
Dotless’s Gmail, Outlook, and SMTP connections are send-only. When you connect one of them, we process connection settings and credentials or tokens needed to test the connection and send messages you direct, together with limited delivery-related metadata made available to the Service. We do not use these connections to read inboxes, sent mail, replies, or address books. Section 2A exclusively governs information received from Google APIs. Customer’s email provider separately processes messages and delivery information under its terms.
Customer is the controller of personal data collected through its published Dotless website and must provide its own privacy notice, lawful basis, consent controls, and rights channel. Dotless processes that form or visitor data for Customer under the DPA except for security, billing, and telemetry processed as an independent controller. A public website must not imply that Dotless is the publisher or controller for Customer’s business.
6. Recipients and service providers
Google user data is disclosed only as described in section 2A and is not included in the broader data flows below. For other data, we disclose only what is reasonably needed for the purpose to:
- infrastructure, database, authentication, storage, hosting, edge-network, analytics, and performance providers;
- payment, invoicing, fraud-prevention, tax, and accounting providers;
- Customer-selected SMTP, email, OAuth, domain, deployment, and other connected providers;
- map, search, collection, business-data, enrichment, validation, AI, image, and code-preview providers used for a requested feature;
- professional advisers, auditors, insurers, financing sources, and transaction counterparties subject to appropriate duties;
- authorities, courts, claimants, or other parties where reasonably necessary to comply with law, protect rights or safety, or establish, exercise, or defend claims; and
- a successor or acquirer in a merger, financing, reorganization, insolvency, or sale of all or relevant assets, subject to applicable notice requirements.
Website analytics on this site uses Google Analytics 4 as the analytics provider named in the first category above. It runs in Google Consent Mode, so it stores data on a visitor’s device only where analytics is accepted in the consent control and otherwise measures through cookieless signals. The Cookie and Storage Notice describes what it collects.
Our Subprocessor Register identifies current named platform providers and their purposes. Dotless does not disclose Customer Content or connected-email credentials for money or cross-context behavioural advertising. Paid Service plans can allow business Customers to view or export business-contact data; some privacy laws may define that disclosure as a “sale” even when the charge is for the Service rather than the individual record. Where such a law applies to Dotless, we will provide the required notice and opt-out, honour legally recognized opt-out signals, and not disclose an opted-out profile in a covered sale. As of this Policy’s effective date, Dotless does not share personal data for cross-context behavioural advertising.
7. International transfers
Dotless is established in Slovakia. Providers and connected services may process data in the EEA, United States, and other countries depending on feature, provider, and configured hosting region. For a transfer from the EEA, United Kingdom, or Switzerland to a country without an applicable adequacy decision, we use an available lawful mechanism such as the European Commission’s Standard Contractual Clauses, the UK Addendum or International Data Transfer Agreement, a recognized certification framework where the recipient validly participates, or another safeguard permitted by law. We assess supplementary measures where required.
You may contact us for information about the relevant mechanism or a copy of applicable safeguards, subject to necessary redactions. Customer transfers governed by the DPA use its transfer framework.
8. Retention schedule
We use the following standard periods, unless a shorter period is requested and feasible or a longer period is required for law, claims, security, or a documented legal hold:
- Account, workspace, projects, and Customer Content: while the account is active; then a 30-day recovery period after a verified deletion request, followed by deletion from active systems. Time-limited encrypted or access-restricted backups are overwritten on their ordinary cycle, targeted at no more than 90 additional days.
- Contract and legal-acceptance evidence: for the business relationship and the applicable limitation period afterward. We retain it longer only while an active dispute, authority requirement, or documented legal hold makes that necessary. After account deletion, we remove direct account data that is no longer needed and minimise or pseudonymise the retained account and email reference while preserving evidence reasonably required to establish, exercise, or defend legal claims.
- Connected-service secrets and tokens: until the integration is disconnected, account is deleted, or the credential is replaced, plus only the limited backup cycle.
- Prospect and business-contact profiles controlled by Dotless: reviewed, refreshed, or deleted based on source age, accuracy signals, use, and objections; an unrefreshed profile is targeted for deletion or re-verification within 24 months. Source, suppression, and objection evidence may be retained longer to prevent re-collection.
- Customer-directed outreach: while Customer’s account is active and under Customer’s configured deletion controls, then the account-deletion schedule above. Minimal suppression records are kept as long as reasonably necessary to honour the opt-out.
- Security, access, and technical logs: ordinarily up to 12 months, with shorter periods where feasible and longer retention only for an incident, abuse investigation, or claim.
- Product analytics: ordinarily up to 14 months before deletion or aggregation, subject to the provider’s configured retention and consent requirements.
- Support and legal correspondence: ordinarily three years after closure, or through an applicable limitation period where needed for a dispute.
- Promotional data: until unsubscribe, consent withdrawal, invalid delivery, or 24 months without meaningful engagement. Consent and unsubscribe evidence may be retained for the applicable limitation period.
- Billing, invoice, tax, and accounting records: ten years or another period required by applicable financial law.
Deletion removes or irreversibly anonymises data unless a narrow exception applies. We may retain a minimal record of a request, suppression, fraud event, payment, or legal claim without retaining content that is no longer needed.
9. Security and incident response
We use technical and organisational measures proportionate to risk, including role-based access, provider-supported encryption in transit and at rest, secret and credential controls, tenant-level database restrictions where applicable, logging, backups, dependency and change controls, personnel confidentiality, incident handling, and vendor review. The DPA contains further measures for Customer Personal Data. No system is completely secure; use a unique password, protect connected accounts, limit workspace roles, and report suspected compromise promptly.
Where required, Dotless will notify affected controllers and authorities of a personal-data breach within the periods applicable to its role and will communicate with affected individuals where the risk and law require it.
10. Your data-protection rights
Depending on applicable law, you may ask us to access, correct, complete, delete, or provide a portable copy of personal data; restrict or object to processing; withdraw consent; opt out of direct marketing, sale, sharing, or targeted advertising where applicable; and appeal a denied request where local law provides that right. You also have the right not to receive unlawful discrimination for exercising a privacy right.
You have an unconditional right to object at any time to processing for direct marketing, including related profiling. You may use an unsubscribe control or email us. For other processing based on legitimate interests, explain your particular situation so we can assess the objection. Where the law requires erasure, Dotless will remove the active profile and retain only a suppression marker needed to respect the request.
Send requests to support@dotless.co. State whether you are a Dotless user, a recipient, or a person in our prospect index and provide enough information to locate the record. We may verify identity and authority proportionately, may not provide information that would adversely affect another person, and will respond within the period required by law. An authorized agent may submit a request where local law permits it, subject to proof of authority.
11. Complaints
Please contact us first so we can investigate. You may also complain to the data-protection authority where you live or work or where an alleged violation occurred. Our lead supervisory authority is the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava 27, Slovak Republic, dataprotection.gov.sk. This does not limit any judicial remedy.
12. Children and personal use
Dotless is not directed to children or available to anyone who lacks legal capacity to enter the agreement. We do not knowingly collect children’s personal data through account registration, and the Service is not offered for personal, family, or household use. Contact us if you believe a child submitted data so we can investigate and delete it.
13. Changes to this Policy
We may update this Policy to reflect legal, technical, or Service changes. We will post the new effective date and provide reasonable additional notice of a material change, such as an account email or in-product notice. If a new purpose is incompatible with the purpose for which data was collected, we will provide any further notice or obtain consent required by law before beginning that processing.
14. Contact
Privacy questions and requests: support@dotless.co, +421 949 086 278, or Saem Group s. r. o., Púpavová ulica 4139/37, 900 25 Chorvátsky Grob, Slovakia. Dotless has not appointed a data protection officer because it has not determined that appointment is legally required; privacy enquiries are handled through this contact.