Privacy Policy
Operator: Saylan Group · Effective date: October 11, 2026 · Last updated: October 11, 2026 · Contact: support@signalsflow.app
This Privacy Policy describes how Saylan Group (“we,” “us,” “our”) collects, uses, and shares information when you visit https://signalsflow.app, request access to Signals Flow, sign in to a workspace, or otherwise use the Signals Flow service (the “Service”). The Service is an invite-only B2B go-to-market platform for ICP scoring, enrichment, verification, and outreach orchestration.
Who we are
Signals Flow is operated by Saylan Group. You can reach us at support@signalsflow.app for privacy questions or requests.
Information we collect
Information you provide
- Access requests: name, work email, company name, company website, background, and expected usage when you submit the request-access form.
- Account credentials: email address and password (or password-reset tokens) when an administrator creates your account or you sign in.
- Workspace content: GTM documents, ICP settings, imported lead and company lists (names, titles, emails, domains, LinkedIn URLs, and related fields), reviewer notes, fit overrides, sequences, and campaign configuration you upload or create in the Service.
- Support messages: content you send through in-app help or contact forms.
- Integration credentials: API keys or campaign IDs you optionally store for third-party outreach or data tools connected to your workspace.
Information collected automatically
- Usage and device data: standard server and application logs (e.g. IP address, browser type, pages viewed, timestamps) when you use the marketing site or authenticated app.
- Authentication session data: session tokens managed through our authentication provider.
- Campaign events: opens, clicks, replies, bounces, and related engagement data returned from connected sending platforms via webhooks.
Information from enrichment and AI processing
When you run enrichment, scoring, or outreach workflows, we send company and person identifiers (such as domains, names, job titles, email addresses, and LinkedIn profile URLs) to subprocessors listed below so the Service can research accounts, score fit, verify emails, generate copy, and push leads to campaigns.
How we use information
- Provide, operate, and secure the Service and your workspace.
- Process access requests and communicate about onboarding.
- Run enrichment, scoring, verification, personalization, and outreach workflows you initiate.
- Store audit history (scores, research notes, reviewer decisions, campaign status).
- Improve prompts, workflows, and product quality using aggregated or de-identified patterns where appropriate.
- Comply with law, enforce terms, and protect rights and safety.
Service providers
We use third-party companies that process data on our instructions to deliver the Service. They fall into the categories below. Optional integrations apply only when you or your administrator configure them.
- Cloud hosting and application infrastructure — runs the marketing site, authenticated application, and server-side processing.
- Database and authentication providers — store workspace data, manage sign-in sessions, and run backend functions.
- AI and machine-learning service providers — GTM profile extraction, company scoring, contact selection, lead intel, sequence generation, final review, and related AI-assisted steps (models are configured in platform settings).
- Web research and data enrichment providers — website scraping, web search, and professional-network or public-source datasets used during company and contact enrichment.
- Email verification providers — validate email addresses for leads in the CRM pipeline.
- Email sending and campaign platforms you connect — when you push leads to campaigns, contact fields and sequence content are sent to the sending platform configured for your workspace; webhooks return engagement and reply events to the Service.
- Transactional email providers — access-request notifications and support messages to administrators and requesters.
- Typography and content delivery — fonts and static assets may load from third-party content networks.
We do not sell personal information. We share data with service providers only as needed to operate the Service, when you connect an optional integration, or when required by law. A current list of service providers is available on request at support@signalsflow.app.
International transfers
Personal data is processed in the United States. Where required by applicable law, we use appropriate safeguards for cross-border transfers, such as Standard Contractual Clauses approved by relevant authorities.
Retention
We retain account and workspace data while your account is active and as needed to provide the Service. After account closure, we delete or anonymize Customer Data within ninety (90) days unless a longer period is required by law. Backup copies may persist for a limited time on their normal roll-off cycle before they are overwritten or deleted.
Security
We use administrative, technical, and organizational measures appropriate to the nature of the data, including access controls, encryption in transit, and separation of tenant workspaces. No method of transmission or storage is completely secure.
Your choices and rights
Depending on your location, you may have rights to access, correct, delete, or restrict certain processing of your personal information, or to object or withdraw consent where processing is consent-based. To exercise rights, contact support@signalsflow.app. We may need to verify your identity and workspace relationship.
Children
The Service is intended for business users and is not directed to children under 16 (or the age specified by applicable law).
Changes
We may update this policy. We will post the revised version on this page and update the effective date. Material changes may be communicated through the Service or email where appropriate.
Related documents
See also our Terms of Service.