Last updated: August 11, 2026
Saazly processes personal data both for its own purposes and on behalf of business customers. Its specific role depends on the data and why it is processed.
Roles and responsibilities
For its own accounts, agreements, security, and support, ICM AS is normally the controller. For a customer company’s visitors, conversations, and attachments, the customer is normally the controller and Saazly the processor. The customer is then responsible for establishing a lawful basis, providing information to data subjects, and issuing instructions to Saazly.
Data Processing Agreement
Processing carried out on the customer’s behalf must be governed by the customer’s applicable Data Processing Agreement (DPA). Contact support for the version of the agreement that applies to your order. A general web page does not replace a signed agreement or its appendices.
Subprocessors and transfers
See our current provider overview. When data is transferred outside the EEA, a valid transfer mechanism and, where necessary, supplementary safeguards must be used.
Data protection in the product
- Access must be limited to the appropriate workspace and role.
- Data collection and AI context must be limited to what the service needs.
- The customer normally controls conversation data and how it is used.
- Requests concerning data subject rights and deletion require identity verification and correct routing.
- Incidents involving customer data are handled in accordance with the DPA and applicable law.
Your rights and data deletion
For a conversation on a customer company’s website, contact that company first. For Saazly’s own account or support data, contact us. Read the Privacy Policy and data deletion information for details.
Contact
ICM AS, company registration no. 995 372 304
Skur 35, Akershusstranda 15
0150 Oslo, Norge
Email: [email protected]