Privacy Policy
Last updated September 26, 2026
Saetta is operated by Vesuvio Labs LLC. This policy explains what data Saetta handles, why, and the choices you have.
Who we are and our role
Saetta connects HaloPSA to Microsoft Teams, Microsoft Outlook, AI assistance and SMS. Our customers are managed service providers (“MSPs”).
- Customer Data. Ticket content, notes, contacts, attachments and SMS conversations that Saetta processes on an MSP's behalf belong to that MSP. For this data Vesuvio Labs acts as a processor (service provider) under the MSP's instructions. The MSP is the controller.
- Account Data. Information about the people who sign in to Saetta (MSP admins and technicians) and about the MSP's subscription. For this data Vesuvio Labs is the controller.
What we collect
Microsoft 365 identity
When you sign in with Microsoft, we receive your name, email address or user principal name, and your Microsoft Entra ID user and tenant identifiers. We use them to authenticate you and to route work to you in Teams and Outlook. Multi-factor authentication and sign-in policies come from your organization's Microsoft 365 settings.
HaloPSA data
With the API credentials an MSP provides, Saetta reads and writes HaloPSA tickets, notes, statuses, time entries, clients, contacts and agents so technicians can work from Teams and Outlook. Most HaloPSA data is fetched on demand and displayed, not copied into Saetta. We store the minimum needed to link records, such as ticket and contact identifiers. Attachments are streamed through short-lived signed links and are not stored by Saetta.
SMS
If an MSP uses the SMS Layer, Saetta stores the phone numbers and message content of SMS conversations between the MSP and its customers, and records those messages on the related HaloPSA tickets.
AI features
When a technician uses an AI feature, such as drafting a reply or summarizing a ticket, the relevant ticket text is sent to an AI inference provider to generate the result. This happens only when AI features are used. Saetta does not use Customer Data to train AI models.
Billing
Subscriptions are processed by our payment processor. Card details are entered directly with the processor and are never stored by Saetta. We keep your plan, seat count and billing identifiers.
Operational data
We keep service logs and error reports to run and secure Saetta. These are designed to exclude message bodies, ticket content and credentials. On our website we use only cookies that are essential for signing in. We do not use advertising or cross-site tracking cookies.
How we use data
- To provide Saetta's features to the MSP and its technicians.
- To secure the service, prevent abuse and troubleshoot problems.
- To bill for subscriptions and send service and account messages.
- To comply with legal obligations.
We do not sell personal information, and we do not use Customer Data for advertising.
SMS and mobile information
We do not sell, rent or share mobile phone numbers or SMS consent information with third parties for their marketing purposes. Text messaging originator opt-in data and consent are not shared with any third parties. Recipients can reply STOP to stop receiving messages and HELP for help. Message and data rates may apply. The MSP that sends messages is responsible for obtaining its recipients' consent.
Sharing
We share data only with service providers (subprocessors) that help us run Saetta, such as hosting, SMS delivery, AI inference, payments and error monitoring. They may use it only to provide their service to us. See our subprocessors. We may also disclose data if required by law or to protect the rights, safety and security of our users and the service.
Security
Data is encrypted in transit. HaloPSA and carrier credentials are encrypted at rest with AES-256-GCM. Each MSP's data is isolated by tenant, and webhooks from connected services are authenticated. See our security overview.
Where data is processed
Saetta and its subprocessors process data in the United States.
Retention and deletion
We keep Customer Data while the MSP's account is active. After an account ends, we delete Customer Data within 30 days of a written request from the MSP. Residual copies in backups are removed in the normal backup cycle. We may keep limited billing records as required by law.
Your rights and choices
Depending on where you live, you may have rights to access, correct, delete or export your personal information. Contact us at hello@saetta.io. If you are a customer of an MSP that uses Saetta, please contact that MSP first. As its processor, we will help it respond.
Children
Saetta is a business service and is not directed to children under 16.
Changes
We will post updates here and change the date above. If a change is material, we will notify MSP admins by email or in the Saetta console.
Contact
Vesuvio Labs LLC — hello@saetta.io. Security issues: security@saetta.io.