Privacy Policy
Version 2.1.1, effective from October 4, 2026
This Privacy Policy explains how Spyral collects, uses, shares and protects personal data when it runs the Spyral platform for document intelligence, annual accounts and bookkeeping workflows, and the website at www.spyral.lu. It also explains your rights and how to use them.
Spyral is offered to businesses only: accounting and fiduciary firms, professionals of the financial sector and other professional firms, with a focus on Luxembourg and the wider Benelux region. When you create an account, you confirm that you are acting for a business. The platform is not offered to consumers.
This English version is the binding text. The Dutch, French, German and Italian versions are translations provided for convenience. If a translation differs from the English version, the English version prevails.
1. Who we are and how to contact us
For the processing that this policy describes as Spyral's own (section 2.2), the controller is:
- Operator
- SPYRAL, S.à r.l.-S (in formation)
- Legal status
- Company in formation under Luxembourg law
- Acting for the company in formation
- Francesco IRENE, Arber FERRA
- Address for correspondence
- 69, rue de Steinsel, L-7254 Bereldange, Luxembourg
- Registered office
- 69, rue de Steinsel, L-7254 Bereldange, Luxembourg
- Trade and Companies Register
- To be published on registration
- VAT number
- To be published on registration
- General and contractual contact
- contact@spyral.lu
- Privacy and data protection
- privacy@spyral.lu
- Security
- security@spyral.lu
- Digital Services Act contact point
- legal@spyral.lu
You can contact us about anything in this policy:
- Privacy and data protection requests: privacy@spyral.lu
- Security incidents and vulnerability reports: security@spyral.lu
- General enquiries: contact@spyral.lu
We have not appointed a Data Protection Officer. Requests sent to privacy@spyral.lu are handled by the people at Spyral who are responsible for data protection.
2. Who this policy covers, and our role
2.1 Who this policy covers
This policy applies to:
- visitors to www.spyral.lu;
- people who use the platform for a customer firm (owners, managers, consultants and other members), and people invited to join a firm's workspace;
- people who request a demo, contact us or receive emails from us;
- business contacts whose professional details we obtain from public sources (section 3.8);
- people who send us a notice under the Digital Services Act (section 3.10).
2.2 Controller or processor
Spyral as processor. The documents a firm uploads or connects, and everything the platform derives from them, are the firm's customer content. Spyral processes the personal data in that content on the firm's documented instructions, and the firm is the controller. The same applies to the information about a firm's own staff that the platform shows to their colleagues (section 4). The firm decides what is uploaded, who can see it and how long it is kept. Our obligations for this processing are set out in the Data Processing Agreement (DPA), which forms part of our contract with every customer. Section 3.4 describes this data so that the people concerned can see how it is handled, but the firm's own privacy notice is the one that applies to them.
Spyral as controller. Spyral decides why and how personal data is processed, and is the controller, for: accounts and authentication; security and abuse prevention; error diagnosis; usage metering and billing; service communications and support; our website and demo requests; prospecting and marketing; records of acceptance of our legal documents; and notices under the Digital Services Act.
If your data is in a firm's workspace. To access, correct or delete personal data held in a firm's workspace, contact that firm, because it decides the outcome. If you write to us instead, we forward your request to the firm concerned where we can identify it, and we help the firm respond, as Article 28(3)(e) GDPR requires.
3. Personal data we process
3.1 Account and identification data
- Your name and business email address.
- When you set up a firm: the firm's name and, if you answer them, the sign-up questions about firm size and main use case.
- Your password, stored only in a one-way form that cannot be turned back into the password. We never store or log it in plain text.
- If you turn on two-factor authentication, the secret behind your authenticator codes, stored encrypted.
- Your membership of workspaces and projects, your roles and permissions, and invitations you send or receive.
- Your interface language, preferences and notification settings, and an optional profile picture.
3.2 Session, security and log data
- Session records: when you signed in, your IP address, and your browser and device (user agent).
- Activity records: security-relevant and administrative actions in a workspace, such as signing in and out, password and two-factor changes, role and permission changes, invitations, data exports, deletions and the closure of a workspace. Each record holds the acting user, the time, the IP address and the user agent. Together these records form the firm's audit trail of who did what.
- Authorisation records: the decisions our permission system takes when someone tries to access a protected resource, with the user, the action, the result, the resource requested, the IP address and the user agent.
- Error records: details of failures that we use to diagnose and fix problems, each identified by a reference code that our support team can look up. Email addresses and similar personal data are redacted from the error text before it is stored. Error reports are also sent to our error-monitoring provider; they identify a user by an internal number, not by name or email address.
- Verification codes: one-time codes for email verification, two-factor sign-in and password resets.
- Rate-limit counters: to prevent abuse, we count requests per sign-in email address, IP address or user. These counters store only a pseudonymised form of the identifier, never the email address or IP address itself.
3.3 Usage and billing data
- Usage records of AI operations, used for billing, plan limits and rate limits. Each record notes which AI service handled the operation and where it was processed (section 7.2).
- Notifications sent to you in the application, and the emails we send you about them.
- Search activity: searches you run in your firm's content, your saved searches and your bookmarks.
- Subscription details: plan, seats, invoices and payment status. Card details are entered on our payment processor's own pages. We never receive or store full card numbers.
3.4 Customer content (Spyral as processor)
- Documents a firm uploads or connects, and the text extracted from them, including text recovered from scanned pages by optical character recognition.
- These documents routinely contain personal data about the firm's staff, its clients and third parties, including directors, managers, shareholders and beneficial owners named in corporate and financial records, and the signatories of contracts and filings.
- Data the platform derives from documents: classifications, extracted attributes, entries in the firm's company and person directories, ownership and management relationships, bookkeeping entries, annual accounts data, and a search index built from document text.
- Data the firm imports from public company registers.
- Conversations with the platform's AI features, including the questions asked and the answers returned; project and shared chats between members; tasks, comments and review notes.
- Corrections that reviewers make to automated output. They are kept so that the platform can apply the firm's own conventions to that firm's later documents. They are never shared with or applied to another firm.
- The names, email addresses and signing status of people asked to sign documents through the platform's e-signature workflow.
3.5 Data from connected services
A firm may connect services it already uses. Each connection is optional, is started by a user of the firm, and can be removed at any time. Access credentials for connected services are encrypted before storage, and are revoked and deleted when the connection is removed or when the account that made it is deleted.
- Cloud storage, file by file: where a user imports files through a cloud storage provider's file picker, only the specific files the user picks, with their name, type, size and dates. See section 6.
- Cloud storage, by folder: where a firm connects a cloud storage account for synchronisation, the contents and metadata of files in the folders the firm designates for synchronisation.
- Electronic signature: the documents sent for signature, the names and email addresses of signers, and the status and audit events of each signature request. A firm can connect its own e-signature account or use the platform's account.
- Team messaging: where a firm links a team messaging workspace or channel, the identifiers needed to link it and the text of commands sent to Spyral from it. Commands that would return content from the firm's documents into the messaging service are switched off. Notifications addressed to an individual user are never posted to a shared channel.
3.6 Support and correspondence
- The content of support requests and of our correspondence with you.
- Records of the issues raised and how they were resolved.
3.7 Website visitors and demo requests
- Our website runs no analytics, advertising or session-recording tools. Our hosting provider processes your IP address and request details to deliver pages and to protect the service against attacks.
- When you request a demo, we store your name, business email address and firm name, send you a confirmation email and alert our team.
3.8 Business contacts from public sources
We sometimes contact businesses that may benefit from Spyral. For this, we collect the professional contact details of people who work at those businesses:
- Data: name, job title or role, employer, business email address, the employer's website domain, industry, location and size, and our own notes on the contact.
- Sources: publicly accessible sources, such as company websites, public company registers and search engine results. Where no address is published, we may derive a likely business email address from the format the company uses, and check with the company's mail server that the address accepts mail.
- Use: to send you a limited number of emails about Spyral. Our prospecting emails may record which of their links were clicked. They do not record whether a message was opened.
- Your choice: you can stop our prospecting emails at any time. Each one has an unsubscribe link at the bottom and a standard unsubscribe header, so that your email app can also offer a one-click unsubscribe button. The link does not contain your email address, does not expire, and unsubscribes you only once you confirm on the page it opens; the one-click button in your email app unsubscribes you directly. When you unsubscribe, we add a one-way hash of your email address to our suppression list (section 11), with the date and whether you used the link or the one-click button. The list never contains the address itself. Before every prospecting email, and every other email that is not part of a service you asked for (such as waitlist updates and announcements), we check the address against the list and send nothing to an address on it. Emails you need for an account, such as security codes and invitations, are not affected. Unsubscribing does not by itself delete the other details we hold about you: you can object at any time, or ask us to delete them, by writing to privacy@spyral.lu. We then delete them by hand and keep only the hash, so that we do not contact you again.
3.9 Records of acceptance of our legal documents
When you accept the Terms of Service, when a firm accepts the Data Processing Agreement, when you acknowledge this Privacy Policy, or when you confirm at sign-up that you are acting for a business, we record which document and version was accepted, a fingerprint of its text, the language you read it in, how it was accepted (for example at sign-up or after an update), the time, your IP address and your user agent, and, for the DPA, the workspace it was accepted for. These records are never edited afterwards.
3.10 Notices under the Digital Services Act
If you report content you consider illegal through our notice form, we process your name and email address, the content you report, your explanation and your statement of good faith, together with our decision and our correspondence with you. We use them to handle your notice and to tell you what we decided.
3.11 Special categories of personal data
The platform is not designed for special categories of personal data under Article 9 GDPR (such as health data, biometric data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, or data concerning sex life or sexual orientation), nor for data relating to criminal convictions and offences under Article 10. Customers are instructed not to upload such data unless they have their own lawful basis and have agreed the necessary measures with us in writing. Because customers control what they upload, we cannot prevent such data from appearing in a document. Where it does, it is protected by the same access controls and security measures as all other customer content.
3.12 Do you have to give us your data?
To create an account, we need your name, a business email address and a password. Without them we cannot give you access to the platform. To pay for a subscription, the firm must give billing details to our payment processor. Everything else, including connected services, a profile picture and the optional sign-up questions, is up to you. No law requires you to provide personal data to us.
4. Information about you that colleagues in your firm can see
The platform helps a firm organise its own work, and some features show members information about each other. For this processing, the firm is the controller and Spyral is the processor (section 2.2). Depending on their role and permissions, colleagues in your firm can see:
- your name, email address, role and profile picture;
- your actions in the workspace, through the activity history and the project activity feed;
- in project analytics: the tasks you completed and the messages you posted in a project, a ranking of the five most active members, and whether you have had no recorded activity in the project for seven days;
- suggestions that name members who uploaded documents on a topic a colleague is asking about or working on.
These features do not take decisions about you. How a firm uses them, for example in organising its staff, is the firm's decision and responsibility, including informing its staff as employment law requires. Ask your firm if you have questions or want to object.
5. Purposes and legal bases
We process personal data only for the purposes below, and not in a way that is incompatible with them (Article 5(1)(b) GDPR). We do not sell personal data and do not use it for advertising.
| Purpose | Our role | Legal basis | Main data |
|---|---|---|---|
| Running the platform for the firm: storing, reading, classifying, searching and analysing customer content, and the features in section 4 | Processor | Determined by the firm as controller. We act under Article 28 GDPR, the Terms and the DPA. | 3.4, 3.5 |
| Creating and administering accounts, workspaces, roles and invitations | Controller | Performance of a contract (Article 6(1)(b)) | 3.1 |
| Securing the service: authentication, two-factor sign-in, sessions, isolation of each firm's data, permissions, rate limiting, and detecting and investigating abuse and incidents | Controller | Performance of a contract (Article 6(1)(b)); legitimate interests in network and information security (Article 6(1)(f), Recital 49) | 3.1, 3.2 |
| Diagnosing errors and keeping the service reliable | Controller | Legitimate interests in a reliable service (Article 6(1)(f)) | 3.2 |
| Metering usage for billing and plan limits, and recording where AI processing took place | Controller | Performance of a contract (Article 6(1)(b)); legitimate interests in being able to show customers where their data was processed (Article 6(1)(f)) | 3.3 |
| Billing, invoicing and accounting | Controller | Performance of a contract (Article 6(1)(b)); legal obligations under tax and accounting law (Article 6(1)(c)) | 3.1, 3.3 |
| Service communications: notifications you configure, security alerts and notices of changes to our legal documents | Controller | Performance of a contract (Article 6(1)(b)); legitimate interests in keeping users informed (Article 6(1)(f)) | 3.1, 3.3 |
| Support | Controller | Performance of a contract (Article 6(1)(b)); legitimate interests in helping users (Article 6(1)(f)) | 3.6, and what is needed to resolve the issue |
| Recording acceptance of our Terms and DPA, and acknowledgement of this policy | Controller | Legitimate interests in being able to prove what was agreed and that information was given (Article 6(1)(f)) | 3.9 |
| Answering demo requests and enquiries | Controller | Steps taken at your request before entering into a contract (Article 6(1)(b)); legitimate interests (Article 6(1)(f)) | 3.7 |
| Prospecting and marketing to business contacts | Controller | Legitimate interests in promoting our services to businesses (Article 6(1)(f)), or your consent where the ePrivacy rules require it (Article 6(1)(a)) | 3.7, 3.8 |
| Measuring and improving the accuracy of automated features, using only review outcomes (whether output was confirmed, corrected or rejected) in aggregated and de-identified form, never document content | Controller | Legitimate interests in improving the service (Article 6(1)(f)) | Review outcomes |
| Handling notices of illegal content | Controller | Legal obligation under the Digital Services Act (Article 6(1)(c)) | 3.10 |
| Meeting legal obligations, answering lawful requests from authorities, and establishing, exercising or defending legal claims | Controller | Legal obligation (Article 6(1)(c)); legitimate interests (Article 6(1)(f)) | As needed |
Where we rely on legitimate interests, we weigh them against your interests and rights before we start, and you can ask us for a summary of that assessment. You can object to such processing at any time (section 12).
6. Google API Services: data collection, use and disclosure
6.1 How the Google Drive integration works
Spyral does not connect to a Google Drive account in the background and does not browse or index a Drive. Instead, a user opens the Google file picker inside Spyral and selects specific files. Google grants Spyral access to those individual files only, so that they can be imported.
6.2 Google API scope requested
- https://www.googleapis.com/auth/drive.file: a per-file scope that grants access only to files the user has explicitly selected or that were created by Spyral. It does not give access to any other file in the user's Drive.
This is the narrowest scope that supports the feature. Spyral does not request broad Drive read access, does not request Gmail or calendar access, and does not request any scope that Google classifies as restricted.
6.3 How Spyral uses Google Drive data
Files imported through the Google file picker are treated exactly like uploaded files and are used only to:
- extract text and make the document searchable within the customer's own workspace;
- classify the document and extract its attributes;
- link it to the companies and people it refers to, within the customer's own directories;
- provide grounded, cited answers when a user asks a question about their own documents;
- feed the customer's bookkeeping and annual accounts workflows.
6.4 Google API Services User Data Policy
Spyral's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6.5 Limited Use requirements
- Limited to user-facing features: Google user data is used only to provide the user-facing features described above.
- No unauthorised transfers: Google user data is not transferred to third parties except as necessary to provide those features, for security purposes, to comply with applicable law, or as part of a merger or acquisition with prior notice to users.
- No human access without consent: our personnel do not read Google user data unless the user has specifically asked us to look at particular content, it is necessary to investigate abuse or a security incident, or it is required by law.
- Binding on all parties: employees, contractors and successors are bound by these requirements.
6.6 What Spyral never does with Google user data
Spyral does not:
- sell Google user data;
- use Google user data for advertising of any kind, including retargeting or interest-based advertising;
- use Google user data to determine creditworthiness or for lending purposes;
- provide Google user data to data brokers or information resellers;
- use Google user data to train or fine-tune any AI or machine learning model.
6.7 Disconnecting Google Drive
Because access is granted per file at the moment of import, there is no standing background connection to revoke. You can still review and remove any authorisation you gave Spyral at myaccount.google.com/permissions. Files already imported into the workspace remain there as customer content and can be deleted in Spyral like any other document, or on request to privacy@spyral.lu.
7. AI processing
7.1 How Spyral uses AI
Spyral uses artificial intelligence (AI) to:
- read documents, including recovering text from scanned pages;
- classify documents and extract their key data, such as parties, companies, people, amounts and dates;
- index document text so that it can be searched;
- answer questions about the firm's documents, with citations to the sources;
- run the Spyral Assistant, which carries out tasks a user asks for in the workspace;
- propose bookkeeping entries and prepare annual accounts data;
- draft and edit text in documents at a user's request, and suggest follow-up questions.
Spyral does not develop its own foundation models. The AI models behind these features are run by external AI providers that we engage as sub-processors (section 9).
When a user asks a question, the platform first searches only that user's own workspace, and only the documents that user is allowed to see. Only the relevant passages found, together with the question, are sent for AI processing. Content from different firms is never combined in a request.
7.2 Where AI processing takes place
AI processing of customer content takes place only in the European Union or the European Economic Area, or in Switzerland, which the European Commission recognises as providing an adequate level of data protection. We verify the processing location with technical controls before an AI service is used, and we never send customer content for AI processing to a location outside these countries: if no AI service in a permitted country is available, the feature concerned is unavailable instead. If we find that a request was processed elsewhere, we stop using that service at once and inform the firms concerned, as clause 11.4 of the DPA provides. For each AI operation, we keep a record of where it was processed (section 3.3), so that we can tell a firm where its documents were processed.
The AI transparency page describes the features that use AI, what each one is used for and where the processing takes place.
7.3 No training on customer data
Spyral does not use customer content, prompts or AI output to train, fine-tune or otherwise improve any AI model, whether its own or a provider's. We send customer content to an AI provider only under terms that prohibit the provider from using it to train its models, and we ask each AI provider for zero data retention, so that it keeps no copy of a request once it has answered. The sub-processor list shows, for each AI provider, whether these terms are confirmed in writing and whether zero data retention is in effect. Where it is not, the provider may keep requests and responses only for the limited period and purposes its data processing terms allow, such as abuse monitoring.
7.4 Human oversight and transparency
- AI output is a proposal. Classifications, extracted data, bookkeeping entries and draft filings are presented for a person to review, and low-confidence output is flagged for review. A person decides whether to accept them.
- When the Spyral Assistant proposes a significant change, such as reclassifying a document, it asks the user to confirm first, and the result is marked for review.
- AI features and AI output are labelled as such in the interface, and AI answers carry a notice that they may be inaccurate and should be checked.
- Exported chat conversations and AI-written document versions carry a machine-readable marker showing that they were generated by AI.
- Used for the intended purpose described in the Terms of Service, Spyral's AI features are not high-risk AI systems under the EU AI Act (Regulation (EU) 2024/1689), and Spyral uses no practice prohibited by Article 5 of that Regulation.
AI output can be incomplete, out of date or wrong. It must be checked before it is used in a filing, a client deliverable or any decision with consequences. The AI transparency page gives more detail, including a register of the AI features.
8. Automated decision-making
Spyral does not make decisions that produce legal effects concerning you, or similarly significantly affect you, based solely on automated processing (Article 22 GDPR). The AI features assist professionals, who review the output and take the decisions. The features in section 4 inform colleagues; they do not decide anything about you.
9. Recipients and sub-processors
We share personal data only as described below, and only as far as necessary.
9.1 Sub-processors
We use service providers in the categories below to host and run the platform. We engage each one under a written contract that meets Article 28 GDPR, which allows it to process personal data only on our instructions and binds it to confidentiality and appropriate security measures. A provider whose contract is not yet in place receives no personal data from us. Services that a firm connects itself are not our sub-processors; they are described in section 9.2.
Service infrastructure
Providers that host, run, secure or deliver the service and process customer data to do so.
| Category | Purpose | Data processed | Location | Transfers outside the EEA |
|---|---|---|---|---|
| Cloud hosting and content delivery | Hosting the application and its server functions, and delivering it to users | All service data in transit; request logs (IP address, user agent) | GermanyThe application is hosted in Germany. A connection may pass through a network location near the user. | Processed in the EEA. Any access from outside the EEA, for support or security, rests on an adequacy decision or standard contractual clauses. |
| Database and file storage | Storing the database and files | Account data, customer documents and their extracted content, chats, activity logs | Germany | Processed in the EEA. Any access from outside the EEA, for support or security, rests on an adequacy decision or standard contractual clauses. |
| Transactional email | Sending transactional email (codes, invitations, notifications) | Recipient email address, name and the email content | Ireland | Processed in the EEA. Any access from outside the EEA, for support or security, rests on an adequacy decision or standard contractual clauses. |
| Error monitoring | Detecting and diagnosing errors in the service (no session recording) | Error details, technical identifiers and request metadata | Location to be confirmed.Not yet confirmed | Any processing outside the EEA rests on an adequacy decision or standard contractual clauses. |
| Abuse protection | Limiting the number of requests to protect the service | Pseudonymised identifiers and request counters | Location to be confirmed.Not yet confirmed | Any processing outside the EEA rests on an adequacy decision or standard contractual clauses. |
| Payments | Subscription billing and payments | Billing contact, company and payment details | Under the provider's own data processing terms.Not yet confirmed | Any processing outside the EEA rests on an adequacy decision or standard contractual clauses. |
| Domain name and email routing | Domain name services and forwarding of email sent to Spyral addresses | Domain name queries; email sent to Spyral addresses | Global network. | May be processed outside the EEA, on the basis of an adequacy decision or standard contractual clauses. |
AI inference
Providers that run AI models on customer content, only at locations in the EEA or Switzerland.
| Category | Purpose | Data processed | Location | Transfers outside the EEA |
|---|---|---|---|---|
| AI inference | Running AI models to read scanned pages, make documents searchable and process text | Document page images, document text and prompts | Finland, FranceData centres in Finland and France.No training on customer data: required by Spyral, written confirmation pending.Zero data retention: requested, not yet confirmed. | Processed in the EEA. Any access from outside the EEA, for support or security, rests on an adequacy decision or standard contractual clauses. |
| AI inference (text processing) | Running AI models for text processing: assistant, extraction, classification and drafting | Document text and prompts sent for processing | European Union, EFTA countries, including SwitzerlandData centres in EU and EFTA countries, including Switzerland.Not yet confirmedData processing agreement not yet signed: Spyral sends this provider no data until it is.No training on customer data: required by Spyral, written confirmation pending.Zero data retention: requested, not yet confirmed. | Processed in the EEA or in Switzerland, which the European Commission recognises as providing adequate protection. |
Features you turn on
Used only when a firm sends a document for signature through Spyral's own e-signature account. A firm's own e-signature account is a service it connects itself (see below).
| Category | Purpose | Data processed | Location | Transfers outside the EEA |
|---|---|---|---|---|
| Electronic signature | Electronic signature requests sent through Spyral's own e-signature account | Signer names, email addresses and the documents to sign | European UnionAn account located in the EU.Not yet confirmed | Processed in the EEA. Any access from outside the EEA, for support or security, rests on an adequacy decision or standard contractual clauses. |
The list is also published at /legal/subprocessors. It describes our sub-processors by category, purpose, the personal data they process and where they process it, and does not name the providers. You can ask us in writing, at privacy@spyral.lu, for the identity of each sub-processor, together with its legal entity, the country in which it and its group are established, the locations where it processes personal data, whether its contract is in place and the safeguards that apply to any transfer. We answer a customer within the times set in clause 8.7 of the DPA, and anyone else as set out in section 12.2. Before we add or replace a sub-processor that processes customer content, we notify customers in advance, stating the category of the new sub-processor, the processing it will carry out and where; its identity is available on request, and a customer can object as set out in the DPA.
9.2 Other recipients
- Members of your firm, according to the roles and permissions the firm sets (section 4).
- Services the firm connects (section 3.5), such as cloud storage, team messaging or the firm's own e-signature account. Data passes to and from them on the firm's instructions, under the firm's own agreement with each provider.
- People asked to sign, who receive the documents sent to them for signature.
- Professional advisers, such as auditors, lawyers and security testers, where necessary for their engagement and under confidentiality obligations.
- Authorities, only where the law or a valid, binding order requires it. We check each request for legality and proportionality, challenge requests that are overbroad or invalid, disclose only the minimum necessary and, where the law allows, tell the affected customer first. We give no government direct or unsupervised access to customer data, and we have built no facility for such access.
The types of service a firm can connect, and what each one receives, are:
| Kind of service | What it receives | When |
|---|---|---|
| Cloud file storage | The files a user picks, or the files in the folders the firm designates, with their name, type, size and dates. The provider sees the selection made in its own file picker. | When the firm connects a cloud storage account, or a user picks files from one. |
| Team messaging workspace | The text of commands sent to Spyral from the firm's messaging workspace, and Spyral's replies. Commands that would return document content are switched off. | When the firm links its messaging workspace. |
| Team messaging channel | Account alerts for the firm, posted to the channel it connects. No client data. | When the firm connects a channel, and only once Spyral sends channel alerts. None are sent at present. |
| Electronic signature (the firm's own account) | The documents sent for signature, and the names and email addresses of the signers. | When the firm connects its own e-signature account and sends a document for signature. |
10. International data transfers
10.1 Where customer content is processed
- The application, the database and file storage are hosted in Germany. Our hosting provider's network receives each request at a point close to the user before passing it on to Germany.
- AI processing takes place only in the EU/EEA or in Switzerland, under the controls described in section 7.2.
- Small parts of customer content can also pass through, or be stored by, the providers that deliver our email and monitor errors: for example, a document name in a notification email, or a fragment of a failed request in an error report. Where these providers process data is shown in the sub-processor list, and clause 11.2 of the DPA sets out the safeguards that apply where it is outside the EU/EEA.
- Messages you send to our email addresses can contain customer content. They are forwarded to the mailbox in which we read them.
- Apart from the above, customer content leaves the EU/EEA only where the firm itself chooses it, for example by connecting a service or by sending documents for signature through an account located elsewhere.
10.2 Providers established outside the EEA
Some of our sub-processors may belong to groups established outside the EEA. Even when data is stored in the EU, such a group may be subject to the laws of its home country, which can require it to give access to data it controls, and its staff or affiliates outside the EEA may have access to some data, for example to provide support or to operate the service. For customer data, the safeguards in clause 11 of the DPA apply.
Where personal data may be accessed from, or transferred to, a country outside the EEA that has no adequacy decision, we rely on:
- the EU-US Data Privacy Framework, where the recipient is certified under it (Article 45 GDPR); or
- the European Commission's Standard Contractual Clauses (Article 46(2)(c) GDPR), together with the supplementary measures that an assessment of the transfer calls for.
Encryption in transit and at rest, and the other measures in section 14, apply to all such data. You can ask for the identity of a given sub-processor, the country in which it and its group are established, and a copy of the safeguards that apply to it, at privacy@spyral.lu.
11. Retention and deletion
We keep personal data only as long as necessary for the purposes in section 5 and to meet our legal obligations. The periods below are applied automatically, except where a row says that the records are reviewed and deleted manually.
| Data | How long we keep it |
|---|---|
| Account data (3.1) | While your account exists. When you delete your account, it is erased at once (see below). |
| Session records | Until the session record expires, 24 hours after it is created. Expired records are then deleted. |
| Verification codes | Deleted 24 hours after they expire. |
| IP addresses and user agents in activity, authorisation and error records | Removed after 90 days. |
| Authorisation records and error records | Deleted after 13 months. |
| Activity records | Kept for as long as the workspace exists, as the firm's audit trail, without IP address or user agent after 90 days. Deleted when the workspace is closed. |
| Notifications | Deleted after 12 months. |
| Usage records | Kept for as long as the workspace exists. Deleted when the workspace is closed. |
| Customer content | For as long as the firm keeps it. The firm decides (see "Deletion by the firm" below). |
| Deleted companies | Kept for 12 months after deletion, then permanently deleted (see below). |
| Workspace exports | The export file and its download links expire 7 days after the export is ready, and the file is then deleted. |
| Error reports at our error-monitoring provider | According to that provider's retention settings, no longer than 90 days. |
| Search history, saved searches and bookmarks (3.3) | While your account exists. Erased when you delete your account, and with the workspace when it is closed. |
| Billing and accounting records | 10 years, as Luxembourg accounting law requires. Reviewed and deleted manually. |
| Records of acceptance of our legal documents (3.9) | For as long as the contract they relate to is in force, and afterwards for the period in which claims about it can be brought. Reviewed and deleted manually. |
| Demo requests | Up to 12 months after our last exchange, unless you become a customer. Reviewed and deleted manually. |
| Business contacts from public sources (3.8) | Up to 24 months after our last contact with you, or until you object, whichever comes first. Reviewed and deleted manually. |
| Unsubscribe records | A one-way hash of your email address, never the address itself, with the date and whether you used the link or the one-click button, kept for as long as we send marketing emails so that we never contact you again. Reviewed and deleted manually. |
| Support correspondence | Up to 3 years after the matter is closed. Reviewed and deleted manually. |
| Notices under the Digital Services Act (3.10) | For as long as needed to handle the notice and any complaint or dispute about our decision. Reviewed and deleted manually. |
| Former trial analytics | Collection has stopped. Any remaining records are deleted automatically 90 days after they were collected. |
Deleting your account. You can delete your account in your settings after confirming your password. You are then signed out everywhere, and the following are erased immediately: your name, email address, password, two-factor settings, preferences, profile picture, notifications, private AI chats, saved searches, bookmarks, search history, memberships and roles, verification codes, and connected cloud storage accounts, whose access is revoked first. IP addresses and user agents are removed from the activity, authorisation and error records about you. A minimal account record without your name, email address or password is kept, so that the firm's records keep a stable author. Work you created for your firm, such as documents, companies, shared chats and ledgers, belongs to the firm and stays in its workspace, and the firm's activity log keeps a record of your actions without your name, email address or IP address. Invitations sent to your address that you never accepted stay with the firm that sent them until it cancels them. Any residual data linked to the account, for example from a task that was still running, is removed within 30 days of the deletion. If you are the only owner of a workspace that still has other members, pending invitations, data or an active subscription, you must first transfer ownership or close the workspace.
Deletion by the firm. The firm controls its customer content. When a document is deleted, the stored file and the data derived from it are removed from the live service. When a company is deleted, it is kept for 12 months, so that a later document about the same company restores it together with its links. After 12 months it is permanently deleted, together with any person records linked only to it. A company that is the subject of a ledger, an annual accounts document or an approval and signature workflow is kept until the workspace is closed, because those are the firm's statutory records.
Closing a workspace. An owner can close the firm's workspace in its settings, after confirming their identity. All members are notified. For 30 days the workspace keeps working, and an owner can export all of its data or cancel the closure. After those 30 days, all of the workspace's data is permanently erased: database records, stored files and search indexes. Members then receive an email confirming the erasure. We keep a minimal record of the closure (the workspace name, who requested it, the dates and how many records were erased) as evidence that the erasure took place. Members' own accounts are not deleted with the workspace; each member can delete their account separately.
Backups. Deleted data can remain in our infrastructure providers' encrypted backups until those backups expire on the provider's schedule. Backups are not used to bring deleted data back into the live service.
We do not claim instant or forensically irreversible erasure. On request, we confirm in writing when a deletion is complete.
12. Your rights
Under the GDPR you have the right to:
- access your personal data and receive a copy of it (Article 15);
- rectification of inaccurate or incomplete data (Article 16);
- erasure, where one of the grounds in Article 17 applies;
- restriction of processing, for example while the accuracy of data is being checked (Article 18);
- data portability: to receive data you gave us in a structured, commonly used, machine-readable format, or have it sent to another provider (Article 20);
- object to processing based on legitimate interests, and at any time to direct marketing (Article 21);
- withdraw consent at any time, without affecting processing already carried out (Article 7(3)).
12.1 In the product
- Correct your details: change your name, email address, language and preferences in your settings.
- Download your data: in your settings, after confirming your password (and your two-factor code if you use one), download a file with the main data linked to your account: your profile, preferences, a list of the documents you uploaded, your chats, recent activity records, search history, bookmarks and saved searches. For a complete copy, write to privacy@spyral.lu.
- Export a workspace: an owner can export all of the firm's data as a ZIP file containing the workspace's records as JSON and CSV files, a manifest describing the format, and download links to all original files. The owner is notified when the export is ready, and it can be downloaded for 7 days.
- Review your sessions: see where you are signed in, and sign out of all devices.
- Delete your account or close a workspace: see section 11.
- Stop marketing emails: use the unsubscribe link in any marketing or prospecting email.
12.2 By request
For anything else, write to privacy@spyral.lu. We may ask you to confirm your identity. We answer within one month. Where a request is complex, or we have received many requests, we may extend this by up to two further months; we tell you within the first month, with our reasons. Requests are free of charge unless they are manifestly unfounded or excessive (Article 12 GDPR). If your request concerns data in a firm's workspace, see section 2.2.
12.3 Complaints
You can lodge a complaint with a data protection supervisory authority, in particular in the EU or EEA country where you live or work, or where you believe the infringement took place (Article 77 GDPR). In Luxembourg, this is the Commission nationale pour la protection des données (CNPD), 15, Boulevard du Jazz, L-4370 Belvaux, Luxembourg, cnpd.public.lu. We would appreciate the chance to address your concern first, at privacy@spyral.lu.
13. Cookies and similar technologies
Spyral uses only cookies and browser storage that are strictly necessary to provide the service you asked for. Under Article 5(3) of the ePrivacy Directive, as implemented in Luxembourg, these do not require consent. That is why we show a one-time information notice instead of a consent banner.
- Cookies keep you signed in, record that you completed two-factor sign-in, protect sign-in and connection flows you start, and remember a language you chose.
- Browser storage remembers interface choices, such as your appearance settings, your favourites, when you last read a project chat, and that you dismissed a notice.
We use no analytics, advertising or social media cookies, no cross-site tracking and no session recording. Our error-monitoring script only reports errors in the application and stores nothing on your device. If you open a cloud storage provider's file picker, that provider's own scripts are loaded and it may set its own cookies under its own terms. Payments take place on our payment processor's own pages.
The full list of cookies and storage keys, with their purpose and lifetime, is in our Cookie Notice. If we ever want to use a cookie or similar technology that is not strictly necessary, we will ask for your consent first and will not use it before you agree.
14. Security measures
We apply technical and organisational measures appropriate to the risk (Article 32 GDPR). No security measure is infallible, and we do not claim that a breach is impossible. In summary:
14.1 Isolation of customer data and access control
- Each firm has its own logically separate workspace. Isolation is enforced at two independent levels: the application checks every request against the user's identity, permissions and workspace before it reads any data, and the database separately enforces the boundary between workspaces, independently of the application.
- We follow secure development practices, including automated checks of access controls.
- Within a firm, access depends on roles and on document visibility (the whole firm, a project team, a restricted group or named individuals). Access is denied by default: a user receives only what their role grants.
14.2 Encryption and credentials
- All traffic between users, the platform and our providers is encrypted in transit with current industry-standard protocols, and browsers are instructed to connect to the platform only over encrypted connections.
- Databases and file storage are encrypted at rest with 256-bit AES encryption.
- Two-factor secrets and access credentials for connected services are additionally encrypted under dedicated keys before storage.
- Passwords are stored only as salted one-way hashes that cannot be turned back into the password (section 3.1). Sign-in cookies cannot be read by scripts, are sent only over encrypted connections and are restricted against use by other websites. A sign-in expires 24 hours after it was last renewed, and the session record 24 hours after you signed in. Changing your password or signing out of all devices ends every existing session at once.
14.3 Application security
- Protection against common web attacks, such as cross-site request forgery, cross-site scripting, clickjacking and content-type confusion, and browser security settings that restrict what our pages may do.
- Strict validation of all input, and validation of uploaded files by their content, not only by their extension.
- Rate limits on sign-in, uploads and AI features, applied to pseudonymised identifiers (section 3.2).
- Error messages shown to users carry a reference code instead of internal details.
- Notifications and live updates in the application are subject to the same authentication and permission checks as all other data.
- Error reports sent to our error-monitoring provider are stripped of passwords, tokens and other credentials, and of document names, before they leave our systems.
- AI processing is restricted to permitted countries by the controls in section 7.2.
14.4 Monitoring and audit
- Security-relevant actions are recorded with the acting user, time, IP address and user agent (section 3.2).
- Errors are monitored with alerting.
- Administrative access that is not limited to a single workspace is restricted to a defined set of functions and to separately controlled privileged access.
14.5 Access by Spyral personnel
Spyral personnel do not access customer content in the ordinary course of operating the service. Access happens only where the customer asks us to investigate a specific problem, where it is necessary to respond to a security incident, or where it is required by law or by a valid order of a competent authority. Such access is limited to what is strictly necessary and is carried out by named personnel bound by confidentiality obligations. Customers subject to professional secrecy can ask us to agree in writing that any such access happens only under their supervision.
14.6 Security assurance
On request, and under a confidentiality agreement, we give customers a description of our technical and organisational measures that is sufficient to complete a vendor security assessment, and we make available the information needed to demonstrate compliance with our processor obligations, as Article 28(3)(h) GDPR requires. The DPA describes these measures in more detail.
15. Security incidents and breach notification
We have an incident response process. Where a personal data breach affects customer data:
- Notification to the customer: without undue delay after we become aware of it, which is the standard Article 33(2) GDPR sets for processors, and in any case within 48 hours, as the DPA provides.
- Information provided: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed, provided in stages if not everything is known at once.
- Assistance: we help the customer meet its own duties to notify the supervisory authority under Article 33 and the people affected under Article 34. If your own regime imposes a shorter or additional reporting duty, tell us and we will agree in writing what we need to do to support it.
- Follow-up: a written summary once the incident is closed, on request.
Report a suspected vulnerability or incident to security@spyral.lu. We aim to acknowledge reports without undue delay and within five business days at the latest, but we do not guarantee a remediation time. We do not take legal action against researchers who report in good faith, act proportionately and give us reasonable time to fix the issue before disclosing it.
16. Data Processing Agreement and customer responsibilities
Our Data Processing Agreement meets Article 28(3) GDPR and forms part of the contract with every customer. It is accepted in the product, for the firm, by a person authorised to manage the firm's workspace. It covers the subject matter and duration of the processing, its nature and purpose, the categories of data and data subjects, processing on documented instructions only, confidentiality, security measures, the authorisation and notification of sub-processors, assistance with data subject rights and with Articles 32 to 36 GDPR, deletion or return of data at the end of the service, audits, and international transfers.
As controller, the customer firm remains responsible for: having a lawful basis for what it uploads; informing the people whose data it processes, including its own staff about the features described in section 4; the accuracy of its data; configuring access correctly within its workspace; carrying out a data protection impact assessment where one is required; deciding how long its content is kept; and reviewing AI output before relying on it.
17. Other EU rules we apply
Beyond the GDPR, the following EU rules shape how the platform is built and contracted. We list them so that customers can see how our obligations meet theirs.
- ePrivacy Directive (2002/58/EC): governs cookies and electronic marketing. We use only strictly necessary cookies and storage (section 13), and every marketing email carries an unsubscribe link.
- AI Act (Regulation (EU) 2024/1689): we use no prohibited practice, and used for their intended purpose our AI features are not high-risk AI systems. How AI use is disclosed and marked is described in section 7.4 and on the AI transparency page.
- Data Act (Regulation (EU) 2023/2854): customers can export all of their workspace data and close their workspace (sections 11 and 12). Our switching and exit commitments are set out in the Terms of Service.
- Digital Services Act (Regulation (EU) 2022/2065): Spyral stores content on behalf of its customers and is a hosting service. Our points of contact and the form for reporting illegal content are on the Digital Services Act page.
- DORA (Regulation (EU) 2022/2554): customers that are financial entities must include specific terms in contracts with their ICT service providers. These are agreed individually: tell us which regime applies to you and what it requires, and we will agree the terms it calls for.
- NIS2 (Directive (EU) 2022/2555): customers within the scope of NIS2 must manage supply chain security. We provide security documentation on request and notify you of incidents affecting the services you receive. Further measures are agreed in writing.
- Luxembourg professional secrecy: customers subject to professional secrecy, including professionals of the financial sector and members of regulated professions, keep duties that continue when they outsource. Confidentiality obligations on our personnel, advance notice of sub-processor changes, and processing of customer content in the EU/EEA (with AI processing also possible in Switzerland, section 7.2) apply as standard. Where a supervisory outsourcing framework applies to you, tell us which one and what it requires of your providers, and we will agree those terms before you upload data covered by the obligation.
- eIDAS (Regulation (EU) No 910/2014, as amended): where the platform is used to obtain electronic signatures, the level of signature depends on the signature service and on the customer's configuration. Customers are responsible for confirming that the level obtained meets the legal requirements of the filing or transaction concerned.
18. Children
Spyral is a business tool. It is not directed at children and is not made available to them. We do not knowingly collect personal data from children. If you believe a child's data has reached us, write to privacy@spyral.lu and we will delete it.
19. Third-party services and links
Our website and the platform may link to third-party services. This policy does not apply to them, and we are not responsible for their practices. Where you connect a third-party service to Spyral, that provider's own terms and privacy policy continue to govern your relationship with it.
20. Changes to this policy
We may update this policy to reflect changes in the law, in our practices or in the service. Each version has a number and an effective date, shown with this page, and the version history below lists every version. Earlier versions remain viewable in the application by users who had an account while those versions were in force, and we send a copy of any earlier version on request to legal@spyral.lu. When we make a material change, we tell users in the application and by email before it takes effect, normally at least 30 days in advance, unless the change is required by law or is needed urgently to address a security risk. Signed-in users are asked to acknowledge a materially changed version, and we record that acknowledgement (section 3.9). Where a change requires your consent, we ask for it rather than assume it.
| Version | Effective from | Status |
|---|---|---|
| 2.1.1 | October 4, 2026 | In force (minor change) |
| 2.1.0 | October 4, 2026 | Superseded |
| 2.0.0 | September 9, 2026 | Superseded |
21. Definitions
- Personal data: any information relating to an identified or identifiable natural person.
- Controller: the party that determines the purposes and means of processing.
- Processor: the party that processes personal data on behalf of a controller.
- Sub-processor: a processor engaged by Spyral to carry out part of the processing.
- Customer or firm: a business that subscribes to Spyral.
- Workspace: the isolated environment belonging to one customer firm.
- Owner: a member of a firm who can manage its billing, export its data and close its workspace.
- Customer content: documents and data uploaded, connected or generated by a customer in its workspace.
- EEA: the European Economic Area, meaning the EU member states plus Iceland, Liechtenstein and Norway.
- Google user data: data accessed through Google APIs, being the content and metadata of files a user selects through the Google file picker.
22. Contact
- Privacy and data protection: privacy@spyral.lu
- Security incidents and vulnerability reports: security@spyral.lu
- General enquiries: contact@spyral.lu