New: Multichannel. LinkedIn + email in one sequence, plus an AI Sales Assistant in every meeting.
Trust

Security & GDPR

Last updated: September 7, 2026

Weezly is operated by a Swedish limited company and processes personal data under the EU General Data Protection Regulation. This page summarizes how customer data is hosted, protected and governed. It complements our Privacy Policy and Terms of Service. For a data processing agreement, security questionnaires or the current sub-processor list, write to support@weezly.com.

Hosting region
European Union (Frankfurt, Germany)
Governing law and authority
Sweden, supervised by IMY
Encryption in transit
TLS 1.2 or newer on every endpoint
Data processing agreement
Available on request for every customer

1. Roles under the GDPR

For website visitors, trial and customer accounts, billing and support, Weezly is the data controller. For the data our customers bring into the product, such as the contacts they message, the conversations in their inbox, the recordings the meeting assistant makes and the videos they generate, the customer is the controller and Weezly is the processor acting on the customer's instructions under a data processing agreement.

The leads database available inside the product consists of professional business contact information licensed from third-party data providers. Weezly does not crawl or scrape LinkedIn or any other platform itself; connectivity runs through licensed API providers. Processing of this data rests on legitimate interest for business-to-business outreach (GDPR Art. 6(1)(f)), and any person can have their record removed by writing to support@weezly.com.

2. Infrastructure and hosting

The website, the application and the production databases run on DigitalOcean infrastructure in Frankfurt, Germany, inside the European Union. Customer data is not moved out of the EU for storage. Where a sub-processor operates outside the EU (listed below), transfers are covered by the EU Standard Contractual Clauses or an adequacy decision.

Production systems are separated from development and staging. Backups are taken on a rolling schedule and retained for a short window so that accidental deletion can be reversed; deleted customer data leaves backups when that window expires.

3. Data protection measures

  • All traffic between users, the application and integrated services is encrypted with TLS.
  • Passwords are stored as salted hashes; session tokens are signed and expire.
  • Access to production is limited to two named engineers on a least-privilege basis, over key-based authentication, and reviewed when roles change.
  • Connected accounts (LinkedIn, Google, Microsoft) use provider-issued tokens that can be revoked by the customer at any time from within the product or from the provider.
  • Sending limits per connected LinkedIn account are enforced server-side and calibrated to each account's LinkedIn SSI to keep customer accounts within safe activity levels.
  • Application and infrastructure logs are retained for troubleshooting and security review and are not sold or shared.
  • Dependencies and the operating system are patched on a regular cadence; security fixes are prioritized.

4. AI features and recordings

AI clone videos are generated from a recording the customer chooses to make of themselves. Customers warrant that they hold the rights and consent for any face or voice they clone; cloning another person without consent is prohibited by our Terms. The meeting assistant joins calls only when the customer enables it, announces itself as a participant where the meeting platform supports it, and can be switched off per meeting. Recordings, transcripts, summaries and drafts belong to the customer, are visible only inside the customer's workspace, and are never used to train models for other customers. Nothing the assistant drafts is sent to a prospect without a human pressing send.

5. Sub-processors

Weezly uses the following categories of sub-processors. Customers with a data processing agreement receive notice of material changes to this list.

ProviderPurposeLocation
DigitalOceanCloud hosting for weezly.com and app.weezly.comFrankfurt, Germany (EU)
Licensed LinkedIn API providerMessaging and profile connectivity for connected LinkedIn accountsEU
Licensed B2B contact data providersThe leads database and email verificationEU / US
AI model, voice and video providersAI clone rendering, transcription, summaries and draftsEU / US
GoogleCalendar and Meet integrations; website analytics (Google Analytics via Tag Manager)EU / US
MicrosoftOutlook calendar and mailbox integrationsEU / US
ZoomMeeting assistant joining Zoom callsUS
Transactional email providerAccount, notification and booking emailsEU / US
Meta, Hotjar, Tidio, PartneroWebsite advertising measurement, session analytics, live chat, affiliate tracking (website only, consent-based)EU / US

6. Your rights and data subject requests

Anyone whose data we hold, whether a customer, a website visitor or a person in the leads database, can request access, correction, deletion, restriction or portability, or object to processing, by emailing support@weezly.com. We answer within 30 days. Requests that concern data a customer processes through Weezly are forwarded to that customer as the controller. Complaints can also be lodged with the Swedish Authority for Privacy Protection (IMY) or your local supervisory authority.

7. Retention and deletion

Account data is kept for as long as the account is active. When a customer deletes their account, or asks us to, workspace data including contacts, conversations, videos, recordings and transcripts is deleted from production and expires from backups within the backup retention window. Billing records are kept for the period Swedish accounting law requires. Website analytics data follows the retention period configured in each analytics tool.

8. Incident response

Security incidents are triaged as soon as they are detected, contained, and documented. Where a personal data breach is likely to result in a risk to individuals, we notify the affected customers without undue delay and the supervisory authority within 72 hours, as the GDPR requires. To report a vulnerability, email support@weezly.com with "Security" in the subject line; we acknowledge reports and do not pursue good-faith researchers.

9. Certifications

Weezly does not currently hold a third-party certification such as ISO 27001 or SOC 2. We answer customer security questionnaires and provide our data processing agreement and sub-processor list on request.