How Sissel handles personal data.
This policy explains how Teklos AS processes personal data when you visit Sissel, create an account, use the service or communicate with us. Effective 7 September 2026.
Two roles, kept separate
Using Google with Sissel? Read about Google sign-in, Google Ads and conversion data, including access, storage and deletion.
1. Who we are and how to contact us
Sissel is operated by Teklos AS, a Norwegian limited company. References to “Sissel”, “Teklos”, “we”, “us” and “our” in this policy mean Teklos AS.
- Legal entity
- Teklos AS
- Organisation number
- 930 284 378
- Country
- Norway
- Privacy contact
- privacy@sissel.app
We have not appointed a data protection officer. Privacy questions and requests can be sent to the contact above.
2. Scope and privacy roles
This policy applies to sissel.app, the Sissel application, account administration, support and our business relationship with customers and prospective customers.
The optional Sissel Ads Performance Chrome extension has a separate extension privacy disclosure describing its narrow advertising-manager permissions, local credential storage and report data.
When Teklos is the controller
Teklos decides why and how account data, service logs, security records, support correspondence and commercial records are processed. This policy applies directly to that processing.
When Teklos is a processor
A Sissel customer decides whether to install the browser SDK, what consent mode to use, which sites and systems to connect, which data to import and which conversions to send. For personal data processed on those instructions, the customer is the controller and Teklos is its processor. The customer’s privacy notice and data processing agreement with Teklos govern that processing.
If Sissel appears on a website you visited or your details came from one of our customers, contact that company first. We will assist the customer with a verified request as required by law and the data processing agreement.
3. Personal data we process
Account and organisation data
- Name, email address, authentication identifier and account creation time.
- Organisation, workspace, membership, role and account preferences.
- Sign-in, session, account-recovery and security information. Password verification is handled by our dedicated authentication service; we do not need to display or recover your password.
Service, device and security data
- IP address, user agent, request time, route, response status, diagnostic information and identifiers needed to operate, secure and troubleshoot the service. Under advertising-measurement consent the visitor’s address is also used to match ad clicks to conversions, and to link visits from the same network address within a short window.
- Audit records about material configuration, access and delivery actions in a customer organisation.
- Messages you send us, contact details and the contents of support or commercial correspondence.
Customer-controlled attribution data
Depending on the customer’s configuration, Sissel can process:
- Site and consent settings, random visitor and session identifiers, consent state, page URL and referrer, event names and timestamps.
- UTM parameters, advertising click IDs, campaign, ad set, ad, keyword and spend data.
- Name, email address, phone number, external customer or record ID, tracking token, selected customer-configured CRM fields and selected form values used to link and describe an identified lead’s consented journey. Selected private values are encrypted and are not added to the minimized event ledger.
- CRM events, lifecycle stages, leads, sales, value and currency, attribution results, reconciliation records and conversion-delivery status.
- Integration settings and encrypted credentials for services the customer chooses to connect.
Sissel does not use browser fingerprinting, buy anonymous enrichment data or combine identity profiles between customers. It may link a browser to a known person when both were seen at the same network address within 72 hours, using the IP address collected under advertising-measurement consent. Such a link is recorded as lower-confidence evidence, is visible as such wherever it is used, and is replaced or revoked as soon as the browser identifies itself. URLs are limited to attribution-relevant parameters, and obvious secrets or personal-data parameters are removed. Customer configuration still matters: customers must not send sensitive or unnecessary data in event names, properties or URLs.
Commercial and legal records
If you enter a paid agreement with us, we process business contact details, the order, invoices, payment status and related accounting records. We do not need full payment card details unless a payment method expressly requires them.
What you must provide
An email address, authentication information and organisation membership are required to create and use an account. Without them, we cannot provide authenticated access. Other profile details and integrations are optional, but a feature may not work unless you provide the data or permission it specifically needs.
4. Where the data comes from
- Directly from you when you register, configure Sissel or contact us.
- From your employer or organisation when it invites or administers your account.
- Automatically from your browser or device when you use the service, including normal server and security logs.
- From a customer’s website, CRM, advertising account or other connected service when the customer instructs Sissel to collect or import the data.
- From identity and integration providers when you or a customer deliberately connect them, within the permissions shown by that provider.
5. Google sign-in, Google Ads and Data Manager
Google sign-in
If you choose to sign in with Google, we receive your Google account identifier, email address and verification status, and available profile information such as your name and picture. Our self-hosted authentication service, Hanko, uses and stores this information to create or link your Sissel account, authenticate you and display your profile. This account information is separate from the customer records used to match advertising conversions. Signing in does not connect a Google Ads account.
Google Ads access and reporting
When an authorised workspace user connects Google Ads, Sissel requests the Google Ads permission (adwords) and the Data Manager permission (datamanager) in a separate Google authorization flow. We store access and refresh tokens so the selected integration can continue working when that user is not signed in.
We use the Google Ads API to list accessible advertising accounts and import the selected accounts’ IDs, names, currency, timezone, campaigns, ad groups, ads, statuses, spend, impressions and clicks. We also read conversion actions and URL tracking settings, and can look up a recorded Google click ID to identify its campaign and ad group. We store this information to show advertising performance and connect observed visits, leads and sales to campaigns. When you configure conversion feedback, Sissel can create the corresponding Google Ads conversion actions.
Google Ads uses the same OAuth scope for read and write operations; it does not offer a narrower reporting-only scope. Data Manager requires its own scope for conversion uploads. The scope descriptions are broader than the operations Sissel performs.
Conversion data sent to Google
When a customer enables live Google conversion delivery, Sissel sends selected first-party lead, sale and other configured outcome events to the customer’s chosen Google Ads account and conversion actions through the Data Manager API. These events come from the customer’s websites, forms, CRM or other configured sources. They support conversion measurement and the customer’s campaign optimisation. Test mode also sends event payloads to Google for validation, without requesting a live conversion import.
Depending on the available data and consent, an upload contains the event time, a transaction identifier for duplicate handling, value and currency, Google advertising click IDs, and matching information. Email addresses, phone numbers and names used for matching are normalised and SHA-256 hashed before transmission. Address matching can also include country and postal code. Hashed identifiers remain personal data; hashing does not make an upload anonymous. We send the recorded consent signals for advertising user data and personalisation, treating an unknown signal as denied.
Customers control the destination account, conversion actions and delivery settings and are responsible for the required notices and consent. Connecting Google Ads does not itself enable live conversion delivery. Google processes the data it receives under its applicable advertising terms and Privacy Policy.
Use and sharing of information received from Google
Sissel’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. These limits also apply to aggregated, anonymised or derived Google data and take precedence over broader permissions elsewhere in this policy.
We use Google data to provide and improve the sign-in, reporting and integration features described here. We do not sell it, supply it to data brokers, use it to build advertising audiences or determine creditworthiness, or use it to train general-purpose AI or machine-learning models.
Google data is available to authorised users in the relevant Sissel organisation and to the infrastructure providers described below as needed to operate those features. Other transfers require your consent to a visible feature, a security need or a legal requirement. A transfer in a merger, acquisition or asset sale requires your prior explicit consent. Our personnel may access Google data only with your agreement to examine specific data, for necessary security or legal purposes, or as aggregated data for permitted internal operations.
Storage, protection and retention
Google account and reporting data is stored in Sissel’s infrastructure as described in the sections below. Requests to Google use HTTPS. Stored Google Ads OAuth credentials and backups are encrypted; role-based permissions, customer isolation and restricted production access protect the data. Account data, imported reports and delivery records follow the retention periods below and the customer’s processing agreement.
Disconnecting, revoking access and deleting data
A workspace administrator can disconnect Google Ads from Sissel’s Integrations page. This stops further imports and conversion delivery through that connection and removes its stored OAuth credentials. Previously imported reports and delivery records remain subject to the retention and deletion rules below; disconnecting does not automatically erase them or data already sent to Google.
You can also revoke Sissel’s access through your Google Account connections. This can affect both Google sign-in and Google Ads access. To request deletion of Google account information or imported Google data held by Sissel, contact privacy@sissel.app and identify the account or workspace concerned. We verify your authority and apply the deletion periods and backup limits below. Requests concerning data already held by Google must also be handled through Google’s applicable controls.
6. Why we use data and our legal bases
When Teklos is the controller, we process personal data for these purposes:
- Provide Sissel
- Create and administer accounts, authenticate users, provide requested features and support customers. The basis is performance of a contract or steps requested before a contract, and our legitimate interest in delivering the service to a customer’s authorised users.
- Secure and operate
- Prevent abuse, isolate customers, maintain audit trails, diagnose faults and protect the service. The basis is our legitimate interest in a secure and reliable service and, where applicable, a legal obligation.
- Communicate
- Respond to enquiries and send necessary account, security, service and contractual notices. The basis is contract, steps requested by you or our legitimate interests.
- Improve Sissel
- Understand limited feature usage and reliability, and improve the product using aggregated or minimised information where practical. The basis is our legitimate interest in improving the service without building advertising profiles.
- Business and law
- Administer agreements and invoices, keep statutory records, establish or defend legal claims and respond to lawful authorities. The basis is contract, legal obligation and legitimate interests.
- Optional marketing
- Send relevant product information where you have consented or where business marketing is otherwise permitted. You can opt out at any time. The basis is consent or legitimate interests, subject to electronic-marketing rules.
Where we rely on legitimate interests, we consider the necessity of the processing and balance our interests against your rights. You can object as described below. The customer, not Teklos, determines the legal basis for customer-controlled attribution data.
9. Where data is processed and international transfers
Sissel’s primary application and database infrastructure is hosted in Finland. Some optional providers selected by a customer—such as advertising, CRM or identity platforms—may process data outside Norway or the European Economic Area under their own arrangements.
If Teklos appoints a provider that transfers personal data outside the EEA, we use a lawful transfer mechanism, such as an adequacy decision or the European Commission’s standard contractual clauses, and assess supplementary safeguards where required. A customer can request the relevant transfer information for its setup.
10. How long we keep data
We keep personal data only as long as needed for its purpose:
- Account and customer relationship data: while the account or agreement is active, then as needed to close the relationship and normally no longer than three years for ordinary contractual claims.
- Customer-controlled data: for the agreed service period. On termination or verified written instruction, we return or delete it according to the agreement; absent a different written period, production data is scheduled for deletion within 30 days.
- Selected CRM fields and form values: until the customer removes the selected field or form, erases the connection or site, or otherwise instructs deletion. Removing a selection stops new retention and deletes the corresponding encrypted values while keeping non-value provenance needed for the event ledger and audit record.
- Collector payloads: pending encrypted batches are scrubbed after 24 hours if processing does not finish. Processed or failed raw receipts are deleted after 30 days.
- Audit records: 25 months, so customers can investigate material changes and delivery actions.
- Security and diagnostic logs: only for the period needed to secure and troubleshoot the service. Logs are rotated with bounded storage; an incident or legal claim can require relevant records to be preserved for longer.
- Backups: deleted data can remain in encrypted, access-restricted backups until those backups expire under the rolling schedule, currently no longer than 12 months. If a backup is restored, prior deletion instructions are reapplied.
- Accounting records: for the period required by Norwegian accounting and bookkeeping law, normally five years after the end of the relevant financial year.
We may retain a limited record longer where law requires it, a dispute is pending or it is necessary to establish, exercise or defend legal claims. Where practical, we anonymise data that no longer needs to identify anyone.
11. Your privacy rights
Subject to the conditions in data-protection law, you can request access to your data, correction, deletion, restriction, portability and information about its use. You can object to processing based on legitimate interests and withdraw consent at any time; withdrawal does not affect earlier lawful processing.
Send a request to privacy@sissel.app. We may ask for information needed to verify your identity and authority. We normally reply within one month and will explain if the law permits more time or if we cannot fulfil a request.
For customer-controlled data, send the request to the company that collected your data. We will support its response. You can also complain to the Norwegian Data Protection Authority (Datatilsynet) or the supervisory authority where you live or work.
12. Automated decisions and attribution
Teklos does not use account data to make decisions that produce legal or similarly significant effects about you. Sissel applies customer-selected attribution rules to observed journeys and can send customer-selected conversion events to connected platforms. Attribution assigns credit under a model; it does not prove that an ad caused a lead or sale. Customers must not use Sissel output as the sole basis for a legally significant decision about a person.
13. How we protect data
We use technical and organisational safeguards designed for the nature of the service, including encrypted transport, customer isolation, database row-level security, role-based access, audit records, encrypted credentials and person identifiers, restricted production access, backups and restore procedures. No online service can guarantee absolute security. Customers must protect their accounts, choose appropriate permissions and tell us promptly about suspected misuse.
More detail is available on our security page and, for production customers, in the data processing agreement and security schedule.
14. Children
Sissel is a business service and is not directed to children. You must be at least 18 to create an account. We do not knowingly collect account data from children. A customer must not use Sissel to collect children’s data unless it has a documented lawful basis and has agreed the use with us in writing.
15. Changes to this policy
We may update this policy when Sissel, our providers or legal requirements change. We will publish the revised policy and its effective date here. If a change materially affects how we use account data, we will also give reasonable notice by email or in the application where required.
16. Contact
Questions, complaints or privacy requests can be sent to privacy@sissel.app.
The contractual rules for using Sissel are in our Terms of Service.