Sales Puppy← Back to site

Privacy Policy

Last updated: 25 July 2026

The short version: we collect the account details you give us and the CRM data you put in the product. We use it to run Sales Puppy for you. We do not sell it, we do not use it to train AI models, and we run no advertising or cross-site tracking anywhere on this site. You can ask us for a copy of your data, or ask us to delete it, at any time.

Who we are

Bizware Solutions Ltd ("we", "us") is a company registered in England and Wales and operates salespuppy.ai and the Sales Puppy application. Sales Puppy is a trading name of Bizware Solutions Ltd.

We are the controller of the personal data described on this page — the account, billing and site data we hold about you directly — within the meaning of the UK GDPR and the Data Protection Act 2018, and of the EU GDPR where it applies to visitors in the EEA.

For the CRM records you upload about your contacts, the position is reversed: you are the controller and we act as processor. We handle that data on your instructions, to provide the service, and for nothing else.

Our registered address is:

Bizware Solutions Ltd207 Regent St.London W1B 3HHUnited Kingdom

Our data protection contact is privacy@salespuppy.ai. For anything else, see our contact page.

What we collect

Information you give us

  • Account and waitlist details — your name and work email address when you join the waitlist, start a trial or create an account.
  • CRM data — the contacts, companies, deals, activities, notes and files you or your team enter or import. This is your data; we process it to run the product for you.
  • Billing details — handled by Stripe. Card numbers go directly to Stripe and are never stored on our systems. We keep the subscription status and invoice records Stripe returns to us.
  • Support messages — what you send us, so we can answer.

Information collected automatically

  • Technical data — IP address, user agent, and approximate region, processed by our hosting provider for delivery, security and abuse prevention.
  • Product usage — which features are used, so we can fix what is broken and improve what is not.

Why we process it

We process personal data on these grounds:

  • To perform our contract with you — to provide, operate, secure and support the product you signed up for, and to bill you.
  • Our legitimate interests — to keep the service secure, prevent abuse, diagnose faults and understand aggregate usage. We balance this against your rights and use the least data that works.
  • Legal obligations — tax, accounting and record-keeping duties.
  • Your consent — for optional product-update emails, which you can withdraw at any time without affecting the service.

We do not sell personal data, and we do not share it with third parties for their own marketing.

AI processing

Sales Puppy uses automated systems to rank leads against your ideal customer profile, detect buying intent, summarise activity, auto-log calls and populate CRM fields.

Your data is never used to train AI models, and model providers do not retain it. Content is sent to a model provider only to serve a request you or your workspace triggered, processed under zero-retention terms, and returned. It does not become training data for us or for anyone else.

AI output is a suggestion, not a decision. Sales Puppy asks before anything irreversible, shows its working, and every action has one-click undo. You are not subject to decisions based solely on automated processing that produce legal or similarly significant effects; a human is always in the loop.

Who we share it with

We share data only with providers who help us run Sales Puppy, under contracts that limit them to acting on our instructions. The complete list:

ProviderPurposeData involvedWhere
Cloudflare, Inc.Application hosting, CDN, securityIP address, request metadataUSA / global edge
Stripe, Inc.Payments, subscriptions, invoicingName, email, card, billing addressUSA
AI model provider(s)Powering the AI features described aboveContent needed to serve a request; zero retention, no trainingUSA

We may also disclose information where the law requires it, or to protect the rights and safety of our users. We will update this table before adding a new subprocessor.

Before launch: name the specific model provider(s) in the row above once the production stack is fixed, and publish the contractual basis for zero retention.

Cookies and tracking

This site runs no advertising, no cross-site tracking and no third-party marketing pixels. We do not use tracking cookies, so there is no consent banner to click.

Fonts are served from our own domain rather than a third-party font CDN, so loading this site does not disclose your IP address to a font provider. Any site analytics we use are cookieless and aggregate, and cannot identify you individually.

The application itself uses strictly necessary cookies to keep you signed in. Those cannot be switched off without breaking sign-in.

International transfers

We are established in the United Kingdom, and the providers listed above operate principally in the United States. Your data may therefore be transferred outside the UK and the EEA.

Where we make a restricted transfer we rely on the safeguards the UK GDPR and EU GDPR permit — the UK International Data Transfer Agreement or the UK Addendum to the European Commission's Standard Contractual Clauses, the Standard Contractual Clauses themselves for EEA transfers, or the UK Extension to the EU–US Data Privacy Framework where a provider is certified under it. We complete a transfer risk assessment before relying on any of them.

Before launch: confirm which mechanism each provider in the table above is actually covered by, and keep the transfer risk assessments on file — the ICO expects them to exist, not merely to be described.

Security

  • Data is encrypted in transit (TLS) and at rest.
  • Access is role-based and limited to what a role needs.
  • Administrative and data-access actions are recorded in an audit log.
  • Single sign-on (SSO) is available on the Whole Pack plan.
  • SOC 2 Type II certification is in progress and not yet complete. We will update this page when it is — we are not claiming a certification we do not hold.

No system is perfectly secure and we will not pretend otherwise. If a personal data breach occurs we will report it to the Information Commissioner's Office within 72 hours where the UK GDPR requires it, and tell affected people without undue delay where the risk to them is high. If you believe you have found a vulnerability, please write to privacy@salespuppy.ai.

How long we keep it

  • Workspace and CRM data — kept while your account is active. After cancellation it is retained for 30 days so you can export or reactivate, then permanently deleted.
  • Billing and tax records — kept as long as applicable tax and accounting law requires, which is longer than 30 days.
  • Waitlist details — kept until launch or until you ask us to remove them, whichever comes first.
  • Support correspondence — kept for up to 24 months.

You can ask for earlier deletion at any time and we will comply except where we are legally required to retain a record.

Your rights

Under the UK GDPR — and the EU GDPR where it applies to you — you may ask us to:

  • confirm whether we process your data, and give you access to it;
  • correct data that is inaccurate, incomplete or out of date;
  • delete data we no longer have a good reason to hold;
  • port your data to another provider in a structured, machine-readable format;
  • restrict or object to certain processing;
  • tell you who we have shared your data with;
  • withdraw consent you have previously given;
  • have a human review decisions made by automated processing.

Write to privacy@salespuppy.ai and we will respond within one month, as the UK GDPR requires. We may need to verify your identity first, and may extend by a further two months for complex requests — we will tell you if that happens. Exercising these rights is free, and we will not treat you differently for doing so.

If you are unsatisfied with our response you can complain to the Information Commissioner's Office, the UK supervisory authority, at ico.org.uk or on 0303 123 1113. If you are in the EEA you may instead complain to your local supervisory authority. We would rather you came to us first.

If your data reached us because a Sales Puppy customer added you to their CRM, that customer is the controller. Contact them directly, or write to us and we will pass the request on.

Children

Sales Puppy is a business product, is not directed at children, and we do not knowingly collect data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.

Changes

We will revise the date at the top of this page when this policy changes. For material changes we will give notice in the product or by email before they take effect.

Contact

Data protection requests and questions about this policy go to privacy@salespuppy.ai. Anything else — sales, support, press — goes to contact@salespuppy.ai, or see the contact page. For commercial or contractual questions, see our Terms of Service.

By post:

Bizware Solutions Ltd207 Regent St.London W1B 3HHUnited Kingdom

Before launch: set COMPANY_NUMBER in src/lib/content.ts and this line appears by itself. A company registered in England and Wales must disclose its registered number on its website (Companies Act 2006 s.82), and it is the identifier that makes Bizware Solutions Ltd verifiable on the public register — the first thing a buyer's procurement team checks.

Before launch: confirm whether Bizware Solutions Ltd needs to pay the ICO data protection fee and appear on the ICO register. Most UK controllers do, the register is public, and buyers look there too.