Slecto privacy statement
This privacy statement explains how Slecto processes personal data for the website, accounts, product guide widgets, product data, analytics, contact forms, result emails and marketing follow-up.
When Slecto is embedded on a customer website, the customer usually determines the purpose and means of processing visitor data. In that case, the customer is controller and Slecto acts as processor.
Privacy by design
Slecto processes only the data needed for product guides, advice, account management, analytics and follow-up.
Consent-aware embeds
Embedded Slecto widgets do not show a separate Slecto cookie banner and can use the consent state of the customer website.
Clear email basis
Result and quote confirmations are transactional. Marketing emails require opt-in or another valid customer-managed basis.
Customer data remains customer data
For embedded guides, Slecto processes visitor data on behalf of the customer unless Slecto determines its own purposes.
1. Who is responsible?
For Slecto's own website, accounts, administration, support and commercial communication, Slecto is controller. Add the final legal entity, registered address, Chamber of Commerce number and privacy contact before publication as a final legal document.
When a customer uses Slecto to show a guide on their own website, the customer usually determines the purpose and means of processing visitor data. The customer must provide their own privacy information to visitors.
Controller: Slecto
Privacy contact: via the contact form
Company details: add final legal entity, address and registration number.
2. Which personal data do we process?
For Slecto's own website, account and support purposes, we may process account details, organization details, contact messages, billing data, technical logs and dashboard activity.
Through guides and widgets, depending on the customer's setup, Slecto may process answers, selected options, flow path, product recommendations, contact details, quote requests, marketing opt-in, consent context and analytics events where allowed.
Slecto is not intended for special categories of personal data unless a separate valid basis, suitable configuration and written arrangement exist.
3. Purposes and legal bases
We process data to provide the service, calculate product matches, send requested emails, manage accounts and organizations, answer support requests, secure the platform and improve product quality.
Depending on the situation, legal bases may include performance of a contract, consent, legitimate interest and legal obligation.
4. Cookies, analytics and embedded widgets
Slecto uses necessary technologies for security, sessions, dashboard access and core guide functionality. Analytics, marketing cookies or comparable tracking may require consent.
On Slecto's own website, statistics and marketing cookies are loaded only after consent. Visitors can accept, reject or configure categories and later reopen cookie settings.
Embedded Slecto widgets do not show a separate Slecto cookie banner. The host website remains responsible for consent and legal basis, and the embed can read host CMP signals, explicit host data attributes or a host consent object where available.
If no valid host consent signal is available, the embedded guide can keep functioning for necessary guide interactions, while analytics, marketing tracking and embedded storage remain disabled. The customer remains responsible for the correct cookie banner, cookie text and privacy information on their own website. Slecto can provide technical support, but does not replace legal review.
5. Email, result emails and marketing
Slecto can send transactional emails when a visitor asks for them, such as a personal product recommendation, result email, quote request or confirmation.
Marketing emails, newsletters, nurture emails and campaign follow-up are sent only when there is a valid opt-in or another applicable legal basis. Unsubscribes, suppression, bounces and complaints are always respected.
6. Sharing with third parties
Slecto shares personal data only when needed for the service, when instructed by the customer or user, or when legally required. This may include hosting, database storage, authentication, email delivery, analytics, security services, support tools, payment or administration services and webshop integrations.
7. Retention
We keep personal data only as long as needed for the relevant purpose, administration, security, legal obligations, disputes or customer instructions. Customers can manage or request deletion of their data.
8. Your privacy rights
Depending on the situation, you may have the right to access, correct, delete, restrict or transfer your data, object to processing, withdraw consent and lodge a complaint with the Dutch Data Protection Authority.
If your request concerns data collected through a guide on a customer website, Slecto may ask you to contact that customer because the customer is usually the controller.
9. Security
Slecto applies technical and organizational measures such as access control, role-based permissions, secure connections, rate limiting, logging, RLS policies, encryption where appropriate and limited data access.
10. Contact and changes
Questions about this privacy statement or personal data can be sent via the contact page. Slecto may update this statement when the service, law or processing changes.
This privacy statement is a careful concept for Slecto, but does not replace legal advice. Add final company details, processor lists and exact retention periods before using it as a final legal document.