Seges
Trust & compliance

Privacy Policy

Effective 13 June 2026 · Connact Inc. (controller)

This policy explains what personal data Connact Inc. (“Connact”, “we”) collects when you use seges.ai and our consulting and data services operated under the Seges practice, why we collect it, how we protect it, and the choices and rights you have. We hold ourselves to one high global standard — the strictest of the laws that apply to us — and add region-specific terms where your country requires them.

At a glance
  • We collect only what we need — today, that is the details you send through our contact form. seges.ai sets no advertising cookies and runs no third-party trackers.
  • We never collect special-category data (health, biometrics, race, religion, political views, criminal records) by design.
  • We ask for your clear, specific consent before we use personal data for analytics, service improvement or AI model training — each as a separate choice you can decline or withdraw.
  • We do not sell your personal data. We do not route it through mainland China, Hong Kong or Macau.
  • You can access, correct, export or delete your data, and withdraw any consent, at any time.

Who we are

The data controller is Connact Inc., a company established in Taiwan (Republic of China), operating the Seges consulting practice at seges.ai. You can reach our privacy team through seges.ai/contact or at zereo@connact.ai.

Where the law of your country requires a local representative or contact point (for example an EU Article 27 representative, or a registered contact in Nigeria, Kenya, India or Indonesia), we appoint one; ask us and we will give you their current details.

What we collect, and why

We tell you, at the point of collection, exactly what we take and what we do with it. For each category we limit collection to the stated purpose:

  • Contact and enquiry data you send us (name, work email, organisation, and the message you write) — to answer you, scope an engagement, and keep a record of our correspondence.
  • Engagement and account data, if you become a client (billing contact, the business information you share for a project) — to deliver and administer the service and meet our legal and accounting duties.
  • Service-usage data from any paid Seges data or API product you use (the queries you run, basic technical logs) — to operate, secure and improve that product.
  • Payment records, processed by our payment provider — we never see or store full card numbers.

The purposes you control

Beyond simply delivering what you asked for, we will only use your personal data for the following purposes if you give us separate, specific consent for each — and you can withdraw any of them at any time without affecting the service itself:

  • Analytics — understanding how our services are used so we can make them better.
  • Service and product improvement — developing new and improved features.
  • Training and improving our AI and machine-learning models — we will tell you plainly when this is the purpose, and we never use special-category data for it.

Our lawful bases

We rely on the most protective basis available where you are. Our primary basis is your consent. Where we provide a service you asked for, we rely on the necessity of performing our contract with you. Where the law of your country recognises it — and only as a secondary basis, never to bypass a consent requirement — we may rely on our legitimate interests in running and improving the service, having weighed those interests against your rights. In several countries (including China, India, Vietnam, Malaysia and Hong Kong) we do not rely on legitimate interest at all; there, the purposes above run only on your consent or on irreversibly de-identified data.

Data we deliberately do not collect

By design, Connact does not collect special-category or sensitive personal data — health, genetic or biometric data, race or ethnicity, religion, political opinions, sex life, criminal records, precise neural data, or government identification numbers. Please do not send us this information. If you do, we will delete it.

Children

Our services are for businesses and professionals and are not directed to children. We do not knowingly collect data from anyone under 18, and we never serve targeted advertising to minors. If you believe a child has provided us data, contact us and we will delete it.

Where your data is processed

We host our services on Google Cloud Platform. By default, personal data of clients in Taiwan and the wider region is processed in Google Cloud's Taiwan region (asia-east1) — it stays on-shore. We do not route personal data through mainland China, Hong Kong or Macau.

When data is processed outside your country, we put a lawful transfer mechanism in place — a data-processing agreement with our providers plus standard contractual clauses or the equivalent your law requires — and, for personal data of people in the EU/EEA and UK, we keep that data in European regions. We describe the specific mechanism for your region below.

How long we keep it, and how we protect it

We keep personal data only as long as needed for the purpose we collected it for, or as the law requires, then delete or irreversibly de-identify it. We protect it with encryption in transit and at rest, access controls, and least-privilege practices. If a personal-data breach occurs, we will notify the relevant regulator and affected individuals within the strictest timeline that applies to us — in most cases within 72 hours of becoming aware — and we keep an internal breach register.

De-identified data

We may create irreversibly de-identified or aggregated data that can no longer be linked to you. Such data is no longer personal data, and we may use it freely — including for analytics and to train and improve our models. We hold ourselves to a high standard of de-identification (data that genuinely cannot be re-identified), and we keep raw personal data out of our training sets.

Your rights

Wherever you are, you can ask us to: confirm what we hold and give you a copy; correct it; delete it; export it in a portable format; restrict or object to a use; object to any direct marketing absolutely; withdraw a consent; and not be subject to a decision based solely on automated processing. These rights cannot be signed away by our terms. Use seges.ai/contact or zereo@connact.ai and we will respond within the strictest period that applies to you (one month in the EU/UK; promptly elsewhere).

Sharing

We share personal data only with service providers who help us run the service (such as our cloud host and payment provider), each under a contract that limits them to our instructions; where the law requires it; or with your direction. We do not sell your personal data, and we do not share it for cross-context behavioural advertising.

Changes

If we change this policy materially we will post the new version with a new effective date and, where appropriate, tell you directly. The version above governs from its effective date.

Your region

Taiwan & Hong Kong

Your data is processed on Google Cloud's Taiwan region by default and is not transferred to mainland China, Hong Kong or Macau. We comply with Taiwan's Personal Data Protection Act (and Hong Kong's PDPO where it applies), including its notice, consent and breach-reporting duties.

Singapore

We comply with the PDPA. For analytics and product improvement we may rely on the Business Improvement Exception; we still tell you the purpose. Transfers are made under a comparable-protection mechanism (our cloud provider's data-processing agreement).

European Union / EEA & United Kingdom

We comply with the GDPR and UK GDPR. Personal data of people in the EU/EEA and UK is kept in European regions; international transfers use the European Commission's standard contractual clauses (or the UK IDTA) with a transfer-risk assessment. You may lodge a complaint with your national supervisory authority, and we will name our EU Article 27 representative on request. You have the right not to be subject to solely-automated decisions that significantly affect you.

California & the United States

We give the notice required by the CCPA/CPRA. We do not sell or share your personal information for cross-context behavioural advertising; we honour the Global Privacy Control browser signal and any “Do Not Sell or Share” request, and we let you limit the use of sensitive personal information. We do not collect neural data.

China (mainland)

Connact does not operate inside mainland China and does not offer these services to users there. If that changes, this policy will be revised to meet the PIPL, including separate consent for any sharing, sensitive data or cross-border transfer.

India

We comply with the Digital Personal Data Protection Act. We give a standalone, itemised notice, rely on your consent, and will support a registered Consent Manager and verifiable consent where required.

Indonesia, Vietnam & Thailand

We provide this policy in the local language where the law requires it, and we put the required transfer mechanism and (in Vietnam) the transfer-impact filing in place before processing your data.

Nigeria, Kenya & South Africa

We comply with the NDPA, the Data Protection Act and POPIA respectively, name the relevant regulator, register where required, and use the approved cross-border-transfer mechanism (including NDPC approval in Nigeria).

Questions about this policy, or a request to exercise your rights? Use seges.ai/contact or write to zereo@connact.ai.

Book a diagnostic