Legal
Privacy Policy
Effective May 22, 2026. Last updated May 22, 2026.
Introduction
This Privacy Policy describes how IGOR ALEKSIĆ PR ALEKSIFA DIGITAL ("Company", "we", "us") collects, uses, shares, and protects personal information when you visit our marketing website at boltsequencer.com, use the Bolt Sequencer application at app.boltsequencer.com, or otherwise interact with us (collectively, the "Sites" and the "Service").
We are registered at Preradovićeva 143, Petrovaradin, Novi Sad 21132, Republic of Serbia. For privacy questions, data subject requests, or data processing agreement (DPA) requests, contact us at support@boltsequencer.com.
This Privacy Policy should be read together with our Terms of Service at Terms of Service on the marketing site. Capitalized terms used but not defined here have the meanings given in the Terms.
By using the Sites or Service, you acknowledge this Privacy Policy. If you do not agree, do not use the Sites or Service.
Scope
This Privacy Policy applies to personal data we process as a business-to-business service provider. The Service is intended for commercial outreach by agencies and businesses, not for personal consumer use unrelated to business activities.
You must be at least 18 years old to create an Account or use the Service. We do not knowingly collect personal data from anyone under 18.
This policy applies to visitors of the marketing site, waitlist signups, Account holders, Users invited to Workspaces, and personal data processed on your behalf when you use the Service.
Definitions
"Personal data" (or "personal information") means information relating to an identified or identifiable natural person.
"Processing" means any operation performed on personal data, such as collection, storage, use, disclosure, or deletion.
"Controller" means the entity that determines the purposes and means of processing personal data.
"Processor" means the entity that processes personal data on behalf of a controller.
"You" or "Customer" means the organization or individual that registers for or uses the Service. "User" means a person who accesses the Service under your Account.
"Lead" or "Prospect" means a person whose contact information you store in the Service or contact through campaigns.
"User Content" has the meaning given in the Terms, including lead records, campaign content, and connected mailbox data you provide.
Controller and processor roles
For personal data of your Leads and contacts that you upload or generate in the Service, you are typically the data controller and we act as a data processor, processing that data on your documented instructions to provide the Service.
You are responsible for providing privacy notices to your Leads, obtaining any required consents, and responding to data subject requests for data you control. We will assist through available product features and support where appropriate.
For Account holder and User personal data (such as name, email, authentication data, billing information, and product communications), we act as a controller for account administration, billing, security, fraud prevention, and Service-related communications.
A data processing agreement for EU/UK business-to-business customers is available on request at support@boltsequencer.com.
Information we collect
The personal data we process depends on how you interact with us. Categories include:
Account and profile data: name, email address, password (stored as a hash), optional avatar, time zone, and workspace membership and role assignments.
Authentication and security data: two-factor authentication enrollment data (encrypted secrets and recovery code hashes), trusted-device tokens, login and session metadata, and security logs.
Workspace and configuration data: workspace names, branding, security settings (such as two-factor requirements), tags, custom fields, blocklists, templates, and campaign configuration.
Lead and User Content: contact details (such as email, name, company, title, phone, website, LinkedIn URL), custom field values, segment membership, campaign enrollment status, and message content you compose or send through the Service.
Connected Inbox data: mailbox email addresses, provider type, OAuth tokens and refresh tokens, SMTP or API credentials you provide, sync cursors, sending settings, and reputation-related metadata stored in the Service.
Messaging and analytics data: outbound and inbound message metadata (such as timestamps, subjects, provider identifiers), optional open and click tracking events when enabled for a campaign, bounce and complaint signals, and aggregated campaign statistics.
Billing data: subscription plan, send-volume quota, payment status, and billing contact details. When you subscribe, payment card or bank details are collected and processed by our payment processor, not stored directly by us except as tokens or references the processor provides.
Support and communications: information you submit through in-app support, email to support@boltsequencer.com, or feedback forms.
Waitlist and pre-launch data: email, optional name, company, job title, country, expected monthly email send volume, and optional LinkedIn profile URL when you join our waitlist on the marketing site.
Marketing site technical data: IP address, browser type, device information, pages viewed, referral URLs, and similar usage data collected through cookies and similar technologies (including Google Analytics, as described below).
We do not intentionally collect special categories of personal data (such as health, biometric, or political data). You must not upload such data to the Service unless we have agreed in writing to appropriate safeguards.
How we use information
We use personal data to provide, maintain, and improve the Service; authenticate users; connect and operate Connected Inboxes on your behalf; send and receive campaign and transactional messages; display unified inbox and analytics; enforce the Terms and protect against abuse, fraud, and security threats.
We use account data to administer billing and subscriptions, send product and security notifications, respond to support requests, and communicate about waitlist or early-access programs.
We use aggregated or de-identified statistics to understand Service performance, diagnose deliverability issues, and improve features. Campaign analytics (such as open and click rates) are reporting tools for your business decisions, not automated legal or similarly significant decisions about individuals.
We may use marketing site analytics to understand how visitors find and use our website, improve content, and measure marketing effectiveness.
We do not sell your personal data.
Legal bases (EEA, UK, and similar laws)
Where the GDPR or similar laws apply, we rely on one or more of the following legal bases:
Performance of a contract — to provide the Service, process your Account, and fulfill our agreement with you.
Legitimate interests — to secure the Service, prevent abuse, improve features, communicate about the Service, and analyze marketing site usage, balanced against your rights.
Legal obligation — to comply with applicable law, lawful requests from authorities, and accounting or tax requirements.
Consent — where required, for example when you join the waitlist and agree to receive related emails, or when you accept non-essential cookies on the marketing site (such as analytics cookies). You may withdraw consent where applicable without affecting the lawfulness of processing before withdrawal.
Waitlist and pre-launch communications
When you submit the waitlist form on boltsequencer.com, we collect the fields you provide (email is required; name, company, title, country, expected monthly sends, and LinkedIn URL may be optional or required as shown on the form).
We use this information to manage early access, understand product demand, and contact you about Bolt Sequencer. When you sign up for the first time, we send a confirmation email to your address and may notify our team of the new signup.
Waitlist confirmation and related administrative emails are sent from mail infrastructure we operate on our servers (see Infrastructure and subprocessors).
You may request deletion of waitlist data by emailing support@boltsequencer.com.
Connected inboxes and third-party mail providers
The Service connects to mailboxes you authorize (Google Workspace / Gmail, Microsoft 365, Amazon SES, or SMTP/IMAP). To send campaigns, sync replies, and detect bounces, we store and use credentials and tokens you provide or obtain through OAuth, and we access the minimum information needed for those functions.
When you connect an account, data may be transmitted to and processed by the relevant provider under that provider's terms and privacy policies. Providers may be located outside the European Economic Area (EEA), including in the United States.
You remain responsible for compliance with your providers' policies and for the lawfulness of messages sent from your Connected Inboxes.
If you connect Google accounts, our use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including the Limited Use requirements.
Google API Services
Bolt Sequencer's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We use Google API data only to provide and improve user-facing features you request (such as sending mail and reading replies through a Connected Inbox), to maintain security, and as otherwise described in this Privacy Policy and the Terms. We do not use Google user data for advertising or sell it to third parties.
Campaign email tracking
Campaigns may optionally enable open tracking (typically a small image pixel) and click tracking (redirect links through our app domain). When enabled, we record events such as opens and clicks, which may include timestamps, IP address, user agent, and associated lead or variant identifiers.
You control tracking settings per campaign. You are responsible for disclosing tracking practices to your Leads where required by law and for honoring opt-out or suppression requests.
Replies sent from Unified Inbox are generally not counted toward send quota and are separate from automated campaign tracking, as described in product documentation.
Marketing site analytics (Google Analytics)
On boltsequencer.com, we use or plan to use Google Analytics, a web analytics service provided by Google. Google Analytics uses cookies and similar technologies to collect information about how visitors use the marketing site (such as pages visited, time on site, approximate geography, device and browser type, and referral source).
Google may process this data as our processor and also use it in accordance with Google's own policies. Learn more at https://policies.google.com/privacy and https://marketingplatform.google.com/about/analytics/.
We use analytics data to understand traffic, improve our website, and measure marketing performance. Where required by law, we will request your consent before setting non-essential analytics cookies.
You can limit analytics collection by adjusting cookie preferences on our site (when available), configuring your browser to block cookies, or using Google's opt-out tools at https://tools.google.com/dlpage/gaoptout.
Infrastructure and subprocessors
We use the following categories of service providers and infrastructure to operate the Sites and Service:
Hosting and database: application and PostgreSQL database hosted on servers we operate with Hetzner Online GmbH in Germany (European Union). Customer and Lead data processed through the Service is primarily stored in this EU location.
Transactional email: verification, password reset, waitlist, scheduled report delivery, and similar administrative messages are sent through mail infrastructure operated on our servers (not a separate mass-market email marketing platform).
Marketing analytics: Google (Google Analytics) for the marketing website, as described above.
Payment processing: when you purchase a Subscription, we use a third-party payment processor to handle payment card data. The processor receives payment details directly; we receive limited billing metadata needed to manage your Subscription.
Mailbox providers you connect: Google, Microsoft, Amazon, and your SMTP or IMAP hosts process data when you send or sync mail through the Service. These providers act under your relationship with them and their policies.
We require subprocessors that handle personal data on our behalf to process it only for the purposes we specify and subject to appropriate confidentiality and security obligations.
International data transfers
We are established in the Republic of Serbia. Primary storage and processing of Service data occurs in Germany (EU) on Hetzner infrastructure.
When personal data is transferred outside the EEA — for example, to Google or Microsoft when you connect those mailboxes, to Google Analytics, or to a future payment processor — we implement appropriate safeguards where required by law, such as Standard Contractual Clauses or reliance on adequacy decisions.
Contact support@boltsequencer.com for information about transfer mechanisms available for your organization.
Security
We implement technical and organizational measures designed to protect personal data, including encryption in transit (TLS) for data sent over networks, encryption for sensitive secrets at rest (such as two-factor authentication keys), access controls, and monitoring for abuse.
Access to production systems and customer data is limited to personnel who need it for their role. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
You are responsible for safeguarding Account credentials, reviewing User access, and configuring workspace security settings such as two-factor authentication requirements.
Data retention
We retain personal data while your Account is active and as needed to provide the Service, comply with law, resolve disputes, and enforce our agreements.
If you do not log in or otherwise use the Service for 6 consecutive months, we may treat the Account as inactive and delete the Account and associated User Content after reasonable notice where practicable, consistent with our Terms.
You should export data you need before cancellation. Messages may remain on your Connected Inbox providers' systems after deletion from our Service.
We may retain limited information (such as billing records, security logs, or anonymized statistics) for longer where required by law or legitimate business needs.
Waitlist data is retained until you ask us to delete it or it is no longer needed for the waitlist program.
Your privacy rights
Depending on your location, you may have rights to access, rectify, erase, restrict or object to processing, data portability, and to withdraw consent where processing is based on consent.
To exercise rights relating to Account or User data we control, email support@boltsequencer.com from your registered address or contact in-app support after signing in. We may need to verify your identity before responding.
For Lead data you control, you should respond to your contacts' requests using your own processes; we will assist where the Service allows and as required for processor obligations.
If you are in the EEA or UK, you may lodge a complaint with your local supervisory authority. In Serbia, you may contact the Commissioner for Information of Public Importance and Personal Data Protection (Belgrade). We encourage you to contact us first so we can address your concern.
US state privacy laws
If you are a resident of California or another US state with a comprehensive privacy law, you may have additional rights regarding access, deletion, correction, and opting out of certain processing. We do not sell personal information as defined by the California Consumer Privacy Act (CCPA), as amended.
To submit a request, email support@boltsequencer.com. We will verify requests as required by applicable law. Authorized agents may submit requests with proof of authorization.
Children and sensitive data
The Sites and Service are not directed to individuals under 18. We do not knowingly collect personal data from children. If you believe we have collected such data, contact support@boltsequencer.com and we will delete it promptly.
Do not submit special categories of personal data (such as health, racial or ethnic origin, or biometric data for identification) to the Service unless we have agreed in writing to appropriate processing terms.
Automated decision-making
We do not make decisions based solely on automated processing that produce legal or similarly significant effects concerning individuals.
Campaign analytics, deliverability metrics, and segment rules are tools you configure; they do not replace your responsibility to comply with applicable law in your outreach.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will post the revised policy on the marketing site with an updated effective date. Material changes may also be communicated through the Service or by email where appropriate.
Continued use of the Sites or Service after the effective date of an update constitutes acceptance of the revised policy, except where law requires otherwise.
Contact and DPA requests
For privacy questions, data subject requests, or to request a DPA, email support@boltsequencer.com.
IGOR ALEKSIĆ PR ALEKSIFA DIGITAL, Preradovićeva 143, Petrovaradin, Novi Sad 21132, Republic of Serbia.
