Vonsel is a business to business sales intelligence and CRM platform. This policy explains what we do with personal data, what your rights are, and how to use them. Vonsel is the controller of the processing described here, and section 1.3 of our Terms of Service identifies who Vonsel is.
This policy forms part of our Terms of Service. Words defined there, such as Workspace, Business Record, Connected Account and Connected Service, have the same meaning here. Where this policy and Annex A to the Terms conflict on the processing of a customer's data, Annex A prevails.
Our Cookie Policy covers cookies, local storage and the analytics that run on our website.
Data protection law assigns responsibility to whoever decides why and how data is processed. We decide that for some data and not for others, so we hold two different roles at the same time.
We are the controller of:
We are a processor, acting on our customer's instructions, in respect of:
This policy describes what we do as controller. What we do as a processor is governed by Annex A to our Terms, the Data Processing Addendum, which sets out our instructions, our security measures, our sub-processors and our deletion obligations. Our customers are the controllers of the data in their Workspaces, and they decide what goes in, who is contacted and for how long the data is kept.
One consequence is worth stating plainly. We do not operate a central contact database that we sell. Workspaces are stored separately, one per customer account. We do not merge them, we do not build a combined corpus out of them, we do not use their contents for our own purposes, and we do not train models on them.
We collect what your browser sends us and what our analytics tools record.
| What | Why | Legal basis |
|---|---|---|
| IP address, browser, device, operating system, language, referring page | Serving the site, security, abuse prevention, and diagnosing faults | Legitimate interest, Article 6(1)(f) |
| Pages viewed, time on page, clicks, navigation paths | Understanding which content is useful and improving the site | Consent, Article 6(1)(a) |
| Session recordings and heatmaps | Seeing where the site confuses people, so we can fix it | Consent, Article 6(1)(a) |
| A referral code, if you arrived through one of our partners | Attributing the referral for up to 30 days | Consent, Article 6(1)(a) |
| What you type into a contact or signup form | Answering you, or creating your account | Legitimate interest, or performance of a contract |
Session replay runs on our public pages only. It is not loaded in the dashboard, in the CRM or in the browser extension. Our Cookie Policy sets out what is stored on your device and how to control it.
Your name, email address, password in hashed form, profile photo if you upload one, business name, sector and website, your language and interface preferences, your plan, and the team members you invite. We need this to give you an account and to run it. Legal basis: performance of a contract, Article 6(1)(b).
Billing name and address, tax identification number, country, plan, invoices and payment history. Card details are entered directly with our payment provider and we never receive or store a full card number. Legal basis: performance of a contract, and legal obligation for invoicing and tax records, Article 6(1)(c).
Registration and last active IP address, the country resolved from that address, a device fingerprint derived from your browser and device characteristics, and a risk score together with flags indicating whether the connection comes from a VPN or a data centre. The fingerprint is calculated when you register and when you sign in, and nowhere else.
We use these to stop one person opening many accounts to abuse free plans, to detect credential stuffing and to investigate incidents. We do not use them for advertising, for tracking you across other websites, or for profiling of any other kind. Legal basis: legitimate interest in preventing fraud and abuse of the Service, Article 6(1)(f).
Requests to our servers, features used, errors, timings, API calls and quota consumption. We use this to keep the Service running, to enforce plan limits, to bill correctly and to decide what to build next. Legal basis: performance of a contract and legitimate interest.
We also run general usage analytics inside the dashboard, subject to your cookie choice. It records which screens and features are used. It does not record what you type, and it does not read the contents of your Workspace. Session recording is not enabled there at all.
What you write to us, what we reply, and any attachments. Legal basis: legitimate interest in answering you, and performance of a contract.
We send you service messages you cannot opt out of while you have an account, such as security alerts, billing notices and changes to these documents.
We also send occasional messages about the Service itself: new features, guidance and offers relating to what you already use. Every one of them carries a one click unsubscribe, and unsubscribing never affects your account or the service messages above. Legal basis: legitimate interest in marketing our own similar products to our own customers, Article 6(1)(f), read with Article 21(2) of Spanish Law 34/2002. Where we want to send you anything outside that, we ask for your consent first and you can withdraw it as easily as you gave it.
When you accept our Terms we record the accepting account, the email address used, the date and time in UTC, the originating IP address and user agent, the exact version identifiers of the documents shown to you, and a cryptographic fingerprint of each text as published at that moment. We keep this so that both of us can prove what was agreed and when. Legal basis: legal obligation and the establishment, exercise and defence of legal claims, Articles 6(1)(c) and 6(1)(f). You can ask us for a copy of your record, and of the exact text you accepted, at any time.
Business Records reach a Workspace one way: a customer captures them.
You capture them yourself, and you are the one who does it. The browser extension runs in your own browser, in your own session, under your own identity and from your own connection. It reads business listings that are already displayed to you, and it can read publicly accessible pages of the websites those listings point to. It does not use proxies, it does not rotate identities, and it does not act for any account but yours. It reads only what the business has made publicly visible, and it does not create, infer or add anything the business has not published itself. What it captures goes into your Workspace, where we hold it as your processor.
We do not supply them. We do not sell business data, we do not hand our customers a list, and we do not run a directory of our own that anyone can search. Where a customer brings in records it already holds through an import interface, those records come from the customer, not from us.
The records are the customer's data and we hold them as that customer's processor. The underlying information is information businesses publish so that customers can find and contact them: trading name, address, coordinates, category, opening hours, telephone number, published email address, website, social profile links, rating and public review text.
What we do not do. We do not use credentials that are not our own, we do not collect data from areas of any service that require a login the customer does not hold, and we do not collect data from private social media profiles, from private message threads, or from any source that is not open to the public.
This section is for you if you own or work at a business whose published details are held in Vonsel, and you want to know why, or you want it to stop.
Where this comes from, and why it is here. It came from you, and it was already public. What is held is what your business published so that customers could find it and get in touch: the entry your business created or claimed on Google Maps, and the contact details shown on your own website. Trading name, address, category, opening hours, telephone number, published email address, website, public social profile links, and the ratings and reviews Google Maps displays to anyone who looks. A customer of ours saved it from their own browser, from pages already displayed to them. Nothing was taken from behind a login, nothing was bought from a list, nothing was guessed, and nothing was added that your business had not published itself.
What we cannot do. We do not control Google Maps, we cannot change or remove your listing there, and we do not keep a directory of our own. If you also want your details to stop being publicly listed at the source, that has to be done with Google. What we can do is act on what sits in our own systems and pass your request to the customer who holds the record.
Who holds it, and who decides. Business details reach Vonsel because one of our customers saved them into their own private Workspace. That customer is the controller of those records. We hold them only as that customer's processor, we do not decide what is collected or who is contacted, and we do not operate a public directory or a shared database of our own.
Being published does not take your rights away, and we do not pretend otherwise. What follows is how to use them.
Your right to object is real, and for direct marketing it is absolute. Under Article 21(3) GDPR you can require that the contacting stop, without giving a reason and without anyone weighing it up. Where the records sit in a customer's Workspace that customer is the controller and must honour it, and we forward your objection to them as set out below. Where we hold data as controller, we stop ourselves.
How to ask. Write to privacy@vonsel.com. You do not need a lawyer and there is no charge. So that we can find the right record and be sure we are answering the right person, tell us:
What we do with your request. Because the records sit inside a customer's Workspace and that customer is the controller, we are not permitted to decide for them. We acknowledge you, we tell you that we act as a processor, and we forward your request to that customer without undue delay and in any event within five business days. We ask that customer to answer you directly. If nobody has answered you within a reasonable time, tell us and we will follow it up with them. Where the request concerns data we hold as controller, listed in section 2, we answer you ourselves within one month, extendable by two months for a complex request, and we tell you inside the first month if we need the extension.
How long it takes to take effect. Answering you and acting in our live systems happens inside the periods above, and in any event within thirty days in a straightforward case. Making a removal effective everywhere takes longer, because a record that has already been copied into a backup disappears with the ordinary backup rotation and is not used in the meantime. Allow up to one hundred and twenty days from your request for that final step. Where a customer of ours has already exported or copied a record outside the Service, that copy is under their control and not ours, and section 12.7 of our Terms places the obligation to act on it on them.
You can also complain to a supervisory authority. In Spain that is the Agencia Española de Protección de Datos, at www.aepd.es. You may instead complain to the authority where you live or work in the EEA.
We do not have access to your email or your messaging accounts unless you deliberately connect them.
If you use the inbox, calendar or messaging module, you connect accounts that belong to you so that you can read and send from inside the Service. When you do:
Providers of accounts you connect, such as your mail or calendar provider, are not our sub-processors. We reach them under the authorisation you grant, and access stops when you revoke it.
Some features use artificial intelligence models operated by third parties, to draft messages, analyse public reviews, score and classify records and transcribe voice notes.
When you use them, the input you provide is transmitted to a model provider acting as our sub-processor. That input may include business details, public review text, whatever you typed, and, for voice notes, the audio and its transcript.
We do not sell personal data. We do not rent, trade or share it for anyone else's marketing.
We use service providers to run the Service, and we describe them by the function they perform: hosting and database infrastructure, payment processing, transactional and marketing email delivery, artificial intelligence model providers, messaging and mailbox connectivity, map rendering, website and product analytics, bot protection, and the content delivery networks that serve fonts and code libraries to your browser.
Annex 3 to Annex A of our Terms sets out, for each category of provider, its purpose, the categories of data it processes, the country of processing and the transfer mechanism. We give the names of the providers themselves to any customer or prospective customer who asks, free of charge and within five business days, as section 12.6 of the Terms provides, and we give at least thirty days' notice before a new sub-processor starts work.
We may also disclose data where we are legally required to, to a court, a regulator or a public authority acting within its powers, to establish, exercise or defend legal claims, or to investigate fraud, abuse or a security incident. If we are ever part of a merger, acquisition or sale of assets, data may transfer with the business, and we will say so beforehand.
Most processing happens inside the European Economic Area. Some does not. Where personal data goes to a country outside the EEA, including at least one country for which the European Commission has not issued an adequacy decision, we rely on:
Each transfer, its destination and its mechanism are set out in Annex 3. You can ask us for a copy of the relevant safeguards at privacy@vonsel.com.
| Data | Kept for |
|---|---|
| Account and profile | While your account is open, then 3 years |
| Invoices, billing and tax records | The period required by Spanish tax and commercial law, currently up to 6 years |
| Record of your acceptance of our documents | The relationship, then 6 years, for the defence of legal claims |
| Server and security logs | Up to 12 months |
| Website analytics | Up to 14 months. The identifiers stored in your browser last longer, and section 3.3 of our Cookie Policy states how long |
| Support correspondence | 3 years from the last message |
| Everything in a customer's Workspace | For as long as that customer decides. On termination they have 30 days to export, after which we delete it, and backups containing it are deleted within 90 days. Annex A, section A11 governs this |
| A record that someone objected or asked to be removed | Indefinitely, limited to the minimum needed to keep honouring the request |
When a retention period ends, data is deleted or irreversibly anonymised.
We encrypt data in transit and at rest, hash passwords, store connected account tokens under a separate key, bind every record to a single customer identifier so that it is retrievable only through it, restrict administrative access to named people on a least privilege basis, and keep application and access logs. Personal data breaches are identified, contained, assessed and notified as set out below.
The full list of technical and organisational measures is published as Annex 2 to Annex A of our Terms. If a personal data breach affects a customer's data, we notify that customer without undue delay, and in any event within 72 hours of becoming aware of it.
No system is perfectly secure and we do not claim otherwise. If you find a vulnerability, or you think an account has been accessed without permission, write to privacy@vonsel.com and we will treat it as urgent.
If you are a customer, or an individual whose data we hold as controller, you can:
Write to privacy@vonsel.com. We answer within one month, extendable by two months for complex or numerous requests, and we tell you inside the first month if we need the extension. We do not charge, unless a request is manifestly unfounded or excessive.
We may ask you to confirm your identity first, only where we genuinely cannot otherwise be sure, and only for what is necessary to be sure.
If we hold your data as a processor for one of our customers, section 6 explains what we do with your request.
You can complain to the Agencia Española de Protección de Datos (www.aepd.es) or to the supervisory authority where you live or work.
This document is dated and versioned. This page shows the date on which it was last updated, and the archive lists every published version with its identifier.
Every version we have published stays available at vonsel.com/legal, each at a permanent address in the form vonsel.com/legal/privacy/<version>, with the date it took effect and a SHA-256 fingerprint of its text. The version in force at the time of a given event governs that event, and the record of your acceptance points to the exact version you were shown.
We may amend this policy. Where a change is material, meaning it reduces your rights, increases your obligations or expands the purposes for which we process personal data, we give at least thirty days' notice by email and inside the dashboard before it takes effect. Other changes, such as correcting an error or updating a contact detail, take effect when published, and we update the version line.
The Service is for business use and you must be at least 18 to hold an account. We do not knowingly collect data from anyone under 18. If we learn that we have, we delete it. If you believe a minor has given us data, write to privacy@vonsel.com.
This service is provided by Vonsel.
Data protection enquiries are answered by us directly.
Last updated: August 7, 2026