Version 9 — effective 30 September 2026.
This Privacy Policy explains how 7Lab B.V., Danzigerbocht 39 G, 1013 AM Amsterdam, The Netherlands (Chamber of Commerce 84815515) ("7Lab", "we") processes personal data as controller when you visit sluis.ai, create an account, or otherwise interact with us. Sluis is a product of 7Lab B.V. You can reach us at info@sevenlab.ai.
Important scope note. Content your organisation sends through the Sluis gateway or Sluis Workspace (prompts, documents, model responses, "Customer Content") is processed by 7Lab as processor on behalf of your organisation, under the Data Processing Agreement between 7Lab and that organisation, not under this policy. The same applies to request metadata that attributes usage to individual users in your organisation's audit trail: 7Lab also processes it for your organisation under the Data Processing Agreement, in addition to our own use of it described below as controller (metering, security, the tamper-evident audit trail, and operating and supporting the Service as described in §2). Questions about Customer Content should go to the organisation that operates your account.
1. What we collect
Account and profile data (when you sign up or are invited): email address, password hash (we never store your password itself) or Google, Apple or Microsoft sign-in identity, full name, phone number, job title, organisation name, country, company size, VAT number (for an EU VAT number from outside the Netherlands, with the result of its verification in the EU VIES system), role and organisation memberships, language preference, and, if you enable two-factor authentication, passkey public keys.
Billing data (when your organisation activates a paid plan): billing and invoice email addresses, payment method type and mandate reference from our payment provider, charge and invoice history, and the VAT details we process for invoicing (country, VAT number and the result of its verification in the EU VIES system). We never receive or store full card numbers or bank credentials; those go directly to Mollie B.V.
Usage and security data: sign-in timestamps, IP addresses on security-relevant events (sign-up, sign-in, legal-document acceptance), operator audit events (who changed what setting, when), request metadata (model, provider, region, token counts, cost) for metering and the tamper-evident audit trail, and technical logs needed to run and secure the Service.
App activity: for each signed-in user and organisation, which Sluis app you opened (web Console, web Workspace, macOS, Windows, Linux, iOS or Android), on which day (UTC), and the app version. The app reports this when you open it and hourly while it is visible; we keep one record per user, organisation, app and day. It is linked to your account, not anonymised. 7Lab operators can see it, and in the operator Users list it appears as your last activity (sign-in, request or app open) and the apps you used in the last 30 days. It is stored only in the Service's own databases (hosted by Scaleway, see §3) and is not shared with anyone else.
Contact data: what you send us through the contact and DPA-request forms or by email.
Local storage: the marketing site and Console store your language choice
(sluis_lang) and session token in your browser's local storage, and the
marketing site stores your cookie choice (sluis_consent). The Console, Sluis
Workspace and the API use no advertising trackers and no third-party
analytics; fonts are self-hosted, so your visit is not disclosed to a fonts
CDN.
Marketing website analytics (only with your consent): on the marketing website (sluis.ai, including its documentation and legal pages; not the Console, Sluis Workspace or the API), we load the Apollo.io website tracker only after you choose "Accept" in the cookie banner. The tracker stores a visitor identifier in your browser's local storage and collects your IP address, the pages you view, the referring page, and browser and device information. It may also load a script from LiveIntent that sets cookies and matches your browser to a hashed (pseudonymised) email address known to LiveIntent, which it passes to Apollo.io. Apollo.io uses this to identify the company you visit from and, where a match exists, you. If you choose "Decline" or make no choice, the tracker is not loaded; if you withdraw consent, we stop it and remove the identifiers it stored in your browser.
2. Why we process it (purposes and legal bases)
| Purpose | Legal basis (GDPR Art. 6(1)) |
|---|---|
| Providing the account, Console and Service | (b) contract |
| Billing, invoicing, tax compliance | (b) contract, (c) legal obligation |
| Security: abuse prevention, throttling, 2FA, audit trails | (f) legitimate interest in securing the Service, (c) where required |
| Recording acceptance of legal documents (who, when, which version, IP) | (f) legitimate interest in proving contract conclusion, (c) accountability |
| Service emails: verification, security notices, invoices | (b) contract, (f) legitimate interest |
| Responding to contact requests | (b)/(f) depending on context |
| Product improvement using aggregated, de-identified metrics | (f) legitimate interest |
| Operating and supporting the Service and understanding which Sluis apps and features customers use (customer success, product improvement), using identified app-usage and request-activity data | (f) legitimate interest |
| Marketing website analytics: identifying which companies and people visit the website (B2B visitor identification) and measuring our marketing (Apollo.io with LiveIntent, marketing website only) | (a) consent, which you can withdraw at any time via "Cookie settings" in the website footer |
We do not use your personal data for automated decision-making with legal effect, and we do not sell it.
3. Who receives it
- Mollie B.V. (Amsterdam, NL): payment processing for paid plans.
- European Commission (VIES; only for a VAT number from an EU country other than the Netherlands): confirms that the VAT number is valid, which the reverse charge on our invoices requires.
- Scaleway SAS (Paris, FR): EU cloud infrastructure hosting the Service and its databases.
- Scaleway SAS (Paris, FR; fr-par): verification, security and invoice emails through its Transactional Email service.
- Google Ireland Limited (for Google accounts in the EEA or Switzerland; otherwise the entity identified in your Google terms; only if you choose "Sign in with Google"): it processes the sign-in under its own terms; we receive your email address and a subject identifier.
- Apple Distribution International Ltd. (Ireland; only if you choose "Sign in with Apple"): it processes the sign-in under its own terms; we receive an email address (which may be an Apple private-relay address) and a subject identifier.
- Microsoft Ireland Operations Limited (for Microsoft Entra work or school accounts in the EEA; otherwise the Microsoft entity your organisation contracts with; only if you choose "Continue with Microsoft"): it processes the sign-in under its own terms and those of your organisation's Microsoft tenant; we receive your email address, your directory (tenant) identifier and your user object identifier.
- ZenLeads, Inc., trading as Apollo.io (United States; only if you accept the cookie banner on the marketing website): website visitor identification and marketing analytics.
- LiveIntent, Inc. (United States; only if you accept the cookie banner on the marketing website, through the Apollo.io tracker): matching your browser to a hashed email address for Apollo.io's visitor identification, under its own privacy policy.
- Competent authorities where the law requires disclosure.
We do not transfer account data outside the EEA in the ordinary course. Marketing website analytics data collected with your consent is transferred to Apollo.io and LiveIntent in the United States under the EU-US Data Privacy Framework where the recipient is certified, otherwise Standard Contractual Clauses. If another transfer becomes necessary, we use an adequacy decision or Standard Contractual Clauses. (Model Providers your organisation enables receive Customer Content, not your account data; that is governed by the DPA and, for non-EU providers, the International Transfer Terms your organisation acknowledged.)
4. How long we keep it
- Account and profile data: for the life of the account and up to 12 months after closure, then deleted or anonymised.
- Billing records and invoices: 7 years (Dutch fiscal retention law).
- Legal-document acceptance records: for the life of the account plus the applicable limitation period, as evidence that the contract was concluded (Art. 17(3)(e) GDPR).
- Operator audit events and request metadata: for the life of the account plus the applicable limitation period (append-only records needed for billing integrity and as compliance evidence); other security logs up to 12 months, longer only where needed for an ongoing investigation.
- Which Sluis app each user opened, per day, with its version: 12 months (365 days), then deleted by the daily automatic purge; also erased when your organisation is erased.
- Marketing website analytics (Apollo.io, with your consent): up to 12 months after the last visit, then deleted. Your cookie choice stays in your browser until you change it via "Cookie settings" or clear your browser storage.
- Prompt and response content retained for your organisation (Customer Content, processed under the DPA): 30 days by default, configurable per organisation. In Sluis Workspace, personal values in conversations are replaced by placeholders after 7 days by default, and conversation history is kept according to your organisation's setting. A daily automatic purge enforces these periods.
- Contact correspondence: up to 24 months after resolution.
5. Your rights
You have the right to access, rectify, erase, and receive a copy of your personal data, to restrict or object to processing based on legitimate interest, and to withdraw consent where processing is based on consent. Write to info@sevenlab.ai; we respond within one month. You can also lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or the authority of your place of residence.
6. Security
We apply the measures described in the DPA's technical-and-organisational annex to all systems, including encryption in transit and at rest for sensitive stores, envelope encryption of credentials, per-tenant isolation, tamper-evident audit chains, and role-based access with mandatory re-verification on every administrative request.
7. Changes
We may update this policy; each version carries a version number and effective date. Material changes are announced in the Console and require acknowledgment before continued use. This document is drafted in English; the English version is the binding one.