Effective date: August 12, 2026 · Version: 1.1
This privacy policy applies to the Seezonee platform and the website at www.seezonee.com. The data controller is 17893833 Canada Inc., a federal Canadian corporation (Canada Business Corporations Act) operating under the name Seezonee (“Seezonee”, “we”, “us”, “our”). The legal entity is the numbered company; “Seezonee” is the operating name.
This policy covers the personal information that Seezonee collects, uses, and discloses through:
This policy does not cover:
The seasonal businesses that use Seezonee are located in Canada and the United States. Their staff may be located anywhere. Seasonal employers recruit internationally, and many staff are contacted while they are still in their home country, months before they travel. Where a staff member is located in the European Economic Area, the United Kingdom, or Switzerland, the additional protections in Section 14 apply to them.
Seezonee plays two distinct roles depending on the data:
This distinction matters: requests from staff members about their personal information are usually handled by the seasonal business that employs them. We will assist the business in responding.
The same split applies under the European and UK data protection regimes, where the terms are “controller” and “processor”: the seasonal business is the controller of its staff data and Seezonee is its processor, acting only on documented instructions under a written processing agreement. Seezonee is the controller of account-holder and billing data.
When a business manager creates a Seezonee account, we collect:
When a business manager imports a staff roster, we collect:
We do not collect: date of birth, parental-consent documents, staff email addresses, home addresses, or health information.
When a staff member replies to a message sent through Seezonee, we collect:
We do not use third-party analytics, advertising trackers, behavioural fingerprinting, or marketing pixels.
We collect personal information for the following named, limited purposes:
We do not use personal information for advertising, profiling, sale, or any purpose unrelated to the operation of the service.
When you use Seezonee to send WhatsApp messages:
We follow Meta’s WhatsApp Business Policy:
When SMS shipping begins (a future stage of the platform), we will follow CASL (Canada) and TCPA (United States) plus Twilio’s toll-free verification requirements. SMS opt-outs are honoured platform-wide.
Inbound WhatsApp media — restricted use. The content of inbound WhatsApp media (images, videos, audio, documents, locations, contacts) that staff send to your business through Seezonee is used only to display conversations to authorized business managers within the Seezonee dashboard, with associated operational housekeeping (security processing such as EXIF stripping and malware scanning, 90-day retention, takedown handling, and audit logging). Inbound media content is not used for: training, fine-tuning, or improving AI / machine-learning models; building advertising profiles, marketing analytics, or any analytics outside the displayed conversation; sharing with third parties, except as required by law or to fulfill Seezonee’s Tech Provider obligations to Meta; any other purpose. These commitments align with Meta’s Platform Terms, Developer Policies, WhatsApp Business Policy, WhatsApp Business Solution Terms, and Policy Enforcement guidelines.
When a business manager connects their WhatsApp Business Account to Seezonee through Meta’s Embedded Signup flow, Seezonee receives:
We use these credentials only to operate the messaging platform on the business’s behalf. We retain them for the duration of the business’s subscription. When a business cancels its subscription, we revoke these credentials within 30 days.
We do not access any Meta asset outside the WhatsApp Business Account that the business explicitly authorized.
Seezonee relies on the following sub-processors. Each one has been chosen for its security posture and contractual data-handling commitments. For each, we list the country, the purpose, and the category of data we send.
We will update this list when sub-processors change and notify customers in advance of any material change.
Seezonee’s “pulse” feature lets a business manager send a question to staff (for example, “How’s your day going?”). Free-text replies are sent to Anthropic for structured aggregation into themes. The output the business manager sees is a summary plus drill-down links — staff identifiers are not sent to the AI provider; only message content is.
This feature operates under the following commitments:
Until those commitments are satisfied for a given seasonal business, the AI feature is not active for that business.
The sub-processors listed in Section 8 are headquartered in or hosted on infrastructure based in the United States. Personal information collected in Canada is therefore stored on, and may transit through, US-based infrastructure.
PIPEDA permits cross-border transfer of personal information provided that organizations use comparable safeguards. We rely on standard contractual terms and the security commitments of each sub-processor to maintain comparable protection.
Personal information about staff located in the European Economic Area, the United Kingdom, or Switzerland is transferred to that same US-based infrastructure. For those transfers we rely on the European Commission’s Standard Contractual Clauses, or on a sub-processor’s certification under the EU–US Data Privacy Framework where it holds one, together with the security commitments described in Section 12. Transfers of UK personal data rely on the UK Addendum to those clauses. Details of the mechanism relied on for a particular sub-processor are available on request.
US authorities may, in some cases, compel disclosure of data held by US-headquartered companies. We will notify our customers of any such request to the extent permitted by law.
We apply the following retention rules:
When data reaches the end of its retention period, it is permanently deleted from production systems. Backups roll off on a 90-day cycle.
We protect personal information through:
Under PIPEDA you have the right to:
In addition, even where not strictly required by Canadian law, we offer a deletion-on-request mechanism. Email privacy@seezonee.com and we will respond within 30 days. We will delete the data subject’s information unless we are legally required to retain it (for example, consent records under CASL).
If you are a staff member of a seasonal business that uses Seezonee, requests about your personal information are usually handled by the business that employs you. Email us anyway — we will help you and the business respond.
To exercise any right, email privacy@seezonee.com. Please describe the request and provide enough information for us to identify you. We may ask for additional verification.
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have further rights and a different complaints route. See Section 14.
This section applies to you if you are located in the European Economic Area, the United Kingdom, or Switzerland. It adds to the rest of this policy; where it conflicts with another section, this section governs for you.
Seasonal businesses recruit internationally, and staff are often contacted while still in their home country. Where that happens, the General Data Protection Regulation (GDPR), the UK GDPR, or the Swiss Federal Act on Data Protection may apply to the handling of your personal information.
The seasonal business that employs or is recruiting you is the controller of your personal information: it decides what to collect and why. Seezonee is its processor and acts only on that business’s documented instructions, under a written processing agreement. For account-holder and billing data, Seezonee is the controller.
The controller relies on one of the following lawful bases, depending on the purpose:
In addition to the rights in Section 13, you have the right to:
You are not subject to any decision with legal or similarly significant effects made solely by automated means. Seezonee does not make such decisions.
Email privacy@seezonee.com. Because the seasonal business that employs you is the controller, we will normally pass your request to it and assist it in responding — but write to us either way and we will make sure the request reaches the right place.
We will respond within one month. If a request is complex, or if you have made several, we may extend that by up to two further months; we will tell you within the first month if that happens, and why. Exercising these rights is free. We may ask for enough information to confirm your identity before we act.
Your personal information is stored on infrastructure located in the United States, as described in Section 10, which also sets out the safeguards relied on for those transfers.
If you are not satisfied with how we or the seasonal business handled your information, you may complain to a supervisory authority:
You may also complain to the Office of the Privacy Commissioner of Canada, as described in Section 13. Contacting us first is not required, but it is usually the fastest route to a fix.
Seezonee is designed for staff at seasonal businesses. Some staff may be under the age of majority.
We do not knowingly collect personal information from children under the age of 13.
If a user reports content as child sexual abuse material (CSAM), Seezonee retains the report and the flagged content beyond normal retention and routes the report to the National Center for Missing & Exploited Children (NCMEC) in the United States (https://report.cybertip.org/) and/or the Canadian Centre for Child Protection (Cybertip.ca) in Canada (https://www.cybertip.ca/), as required by law. Retention and routing follow our legal obligations under the U.S. REPORT Act (18 U.S.C. § 2258A) and Canada’s Mandatory Reporting Act.
The www.seezonee.com marketing website runs on Webflow. It uses Webflow’s default cookies for site delivery and may set a small number of essential cookies. We do not run advertising trackers, social-media pixels, or behavioural-analytics scripts on the marketing site.
The Seezonee web application uses only essential cookies — a Supabase-issued authentication session cookie. We do not run analytics, advertising, or behavioural tracking inside the application.
We will update this policy as our practices evolve. For material changes:
The current effective date and version are at the top of this page. Prior versions are available on request from privacy@seezonee.com.
For any privacy question, request, or complaint: