Legal

Privacy Policy

Last updated: 7 September 2026

1. Who is responsible for your data

Seyreon decides why and how the personal data described here is used — in data-protection language, we are the controller, and under India's Digital Personal Data Protection Act, 2023 (the DPDP Act) the Data Fiduciary. Our registered address is 27, Near Jain Mandir, Ward No. 27, Mohalla Number 2, Bilsi, Budaun, Uttar Pradesh 243633, India, and we work from Delhi.

This policy is written to meet the DPDP Act and, for visitors in Europe and the UK, the GDPR. In short: we save your details only to answer you and to make the next conversation better, we keep them safe, we never sell them, and you can have them erased whenever you like.

For anything in this policy — a question, a correction, a copy of your data, or a deletion — write to support@seyreon.com or use the contact page. We answer within 30 days, usually much sooner.

2. What we collect, and when

We collect only what the thing you are doing actually needs. Nothing on this list is bought from a data broker or scraped from elsewhere.

Just visiting

Our server keeps ordinary technical logs — IP address, browser, the page requested, the time — for security and troubleshooting. Blog view counts are anonymous: a post you are reading is marked in your browser's own session storage so one person is not counted twice, and no identifier for that ever leaves your device.

Contact form

Your name and email, plus the phone number, company and message you choose to add — so a person can reply.

Newsletter

Your email address and the date you subscribed. Every mail carries an unsubscribe link, and one message to us stops them immediately.

The chat assistant (Reon)

The name and email you give during the short intro, your answers to the intro questions, your browser timezone, the conversation itself, a short summary of it, and a note of your preferences so the assistant is more useful next time.

Why the intro is “once per device”, and why you may still be asked again. Reon recognises you by a random identifier stored in the browser you are using — not by tracking you around the web, and not by any account or password. That marker exists only in that one browser on that one device. A new phone, a different browser, a private window, or clearing your browsing data all leave nothing for Reon to find, and it will ask for your email once more. Giving the same address joins that device to the history you already have; it does not create a second profile of you. This is a trade we chose deliberately: no cross-site tracking, at the cost of the occasional repeat question.

Please don't type passwords, card numbers, government ID numbers or health information into the chat. It is not the place for them.

Want everything Reon knows about you gone? Email support@seyreon.com from the address you gave the chat, say “delete my Reon data”, and we erase the conversations, the summaries, the preferences and your name and email — permanently, not just from the screen. No form, no questions asked.

Live chat with a person

The transcript of the conversation and which of our team handled it.

Booking a meeting

The time you chose, your timezone, the topic, your name and email, and any addresses you ask us to invite. If the meeting is placed on a Google Calendar, those details go to Google as part of the invitation.

Testimonials and case studies

If you submit a testimonial: your name, role, company, photo and words. We publish them only because you submitted them, and we take one down on request. A case study naming a client is published only with that client's agreement.

Client portal

The account our team creates for you (name, company, email, phone, billing email) and everything you place in the portal: messages, tickets and their attachments, documents, calendar entries and vault entries. Vault secrets are encrypted at rest with a key held outside the database.

Invoices and payment

The billing details on your invoices, what was invoiced, the amounts, the due dates, and whether an invoice was settled. If you tell us you have paid, we record that you pressed the button and when. We never see or store card or bank details — a payment link on an invoice takes you to the payment provider's own page, and only they handle those numbers.

Team accounts

For people who work with us: their account details, the permissions they hold, when they last signed in, and an activity trail kept for 7 days.

3. Cookies and browser storage

We use no advertising cookies and no ad trackers. We do use Google Analytics on the public pages, to count how many people visit and which pages they read. It is the only third party that sets a cookie here, and it is never loaded inside the admin or the client portal. What is on this site:

  • Sign-in cookies — set only after you sign in to the admin or client portal, so the site knows the session is yours. They are strictly necessary; without them there is no way to stay signed in.
  • Google Analytics cookies — on the public pages only. They count visits, which pages get read and roughly which country and source a visit came from, so we know what is worth writing more of. They never carry your name or your email, we have turned on no advertising features, and blocking them changes nothing about how this site works for you.
  • Local storage — the random chat identifier described above, whether you muted the click sound, whether spoken replies are on, and whether the portal sidebar is collapsed. All of it stays in your browser.
  • Session storage — a marker so a blog post you are reading is counted once.

Clearing your browser data removes every one of these. The sign-in cookies will simply sign you out; the rest is forgotten preferences.

4. Why we use it, and our legal basis

  • To do the work you asked for — running your portal, answering messages, holding meetings, issuing invoices. Basis: performance of a contract, or steps taken before entering one.
  • To reply to enquiries — including reading intro answers and finished conversations, with the help of an AI model, to spot the ones a person should answer personally. Basis: our legitimate interest in running a business and answering the people who contact us.
  • To send the newsletter and other marketing mail. Basis: your consent, which you can withdraw at any time.
  • To keep the site and portal safe — server logs, sign-in records, rate limits. Basis: our legitimate interest in security.
  • To meet the law — keeping invoicing and tax records for as long as we are required to. Basis: legal obligation.

We do not sell personal data, and we do not use it to advertise to you anywhere else.

5. How long we keep it

Most of what we hold deletes itself on a schedule, and the screen showing it always prints how long each item personally has left. The current rules:

  • A conversation with Reon on this websitedeleted 30 days after the last message
  • A live-chat transcript with a persondeleted 7 days after the chat ends
  • A chat with Reon inside the client portaldeleted 7 days after the session ends
  • A note our AI made that you might want to hear from usdeleted 15 days after it is made
  • A message sent through the contact formdeleted 7 days after it arrives
  • A resolved message-box ticket and its attachmentsdeleted 7 days after it is resolved
  • A finished meeting's recorddeleted 2 days after the meeting ends
  • A meeting somebody deleteddeleted 2 days after it was removed
  • A record of one sign-in to the portaldeleted 7 days after it happens
  • A record that we sent you an emaildeleted 7 days after it is sent
  • What our own team did inside the admindeleted 7 days later
  • Anything deleted by handrecoverable from our Delete Bin for 7 days, then gone for good

Your account, your name and email, your intro answers, your documents and your invoices are kept while you are working with us, and afterwards only for as long as we need them — invoicing and tax records for the period the law requires, everything else until you ask us to delete it. You never have to wait for a sweep: ask, and we remove it.

6. Who else sees your data

Only the companies that make the service work, each handling data on our instructions:

  • Supabase — our database, sign-in system and file storage.
  • Sanity — the content behind our blog and case studies.
  • OpenAI — generates the assistant's replies and the summaries; it receives the text of the conversation for that purpose.
  • Our email provider — sends the mail you get from us: replies, invoices, reminders, the newsletter.
  • Google Analytics — counts visits to our public pages; it receives your IP address and the pages you looked at, not your name.
  • Google Calendar — only if a meeting you booked is placed on a calendar.
  • Our hosting provider — runs the servers this site is on.
  • A payment provider — if you pay an invoice online, your payment details go to them, never to us.

The services we use to illustrate and research our own blog posts (Pexels, Unsplash, Brave Search) and the exchange rates on the pricing page (the European Central Bank via frankfurter.dev) receive no personal data at all.

We may also disclose data where the law requires it, or to establish or defend a legal claim. If our business is ever transferred, your data moves with it under this same policy.

7. Where your data is held

We operate from India, and the providers above run in various countries, so your data may be processed outside the country you live in — including outside the EEA and the UK. Where that happens we rely on those providers' standard contractual clauses and equivalent safeguards. Ask us and we will tell you which provider holds what.

8. How we protect it

Traffic is encrypted in transit. Sign-in is handled by Supabase, and every admin and portal page checks the session on the server before it renders — a correct password for the wrong door does not leave a live session behind. Vault secrets are encrypted at rest. Uploaded files live in private storage and are served through short-lived links. Access is limited to the people who need it, and what our own team does inside the admin is recorded for 7 days. No system is perfect; if a breach ever affects you we will tell you, and the relevant authority, as the law requires.

9. Your rights

Wherever you live, you can ask us to:

  • Show you what we hold about you.
  • Correct anything wrong or out of date.
  • Delete your chat history, your learned preferences, or everything we hold.
  • Export a copy in a portable format.
  • Restrict or object to a particular use, including anything we do on a legitimate-interest basis.
  • Withdraw consent — for the newsletter or anything else you agreed to — without affecting what was done before.
  • Nominate someone to exercise these rights for you if you are unable to.

One message to support@seyreon.com or the contact page is enough — no form, no fee. If you are unhappy with how we handle it, you can complain to your data-protection authority: in India the Data Protection Board, in the EEA or the UK your national supervisory authority.

10. Children

This is a service for businesses. It is not directed at children, and we do not knowingly collect data from anyone under 18. If a child's data has reached us, tell us and we will delete it.

11. Automated decisions and AI

Reon writes its own replies, and an AI model helps us sort enquiries and summarise conversations. None of that decides anything about you on its own — a person makes every decision that affects you, including whether we work together, what we quote, and anything to do with money. You can always ask for a human instead of the assistant.

12. Changes to this policy

If we change it, the date at the top changes with it. For a change that materially affects you we will say so by email or in the portal, rather than quietly editing the page.

13. Contact

support@seyreon.com · +91 63988 00516 · contact page. Invoicing questions: billing@seyreon.com.