PRIVACY

Privacy Policy

Spotless Technologies Limited is committed to protecting the personal information you share with us. This policy explains what we collect, why we collect it, and the choices you have around your data.

CONTENTS
01Overview
02Information We Collect
03How We Use Your Data
04Data Sharing & Disclosure
05Data Retention
06Security
07Cookies & Tracking
08Your Rights
09International Transfers
10Contact
01

Overview

Spotless Technologies Limited (“Spotless”, “we”, “us”, or “our”) is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our software-as-a-service (SaaS) products, website, and services.

By accessing or using the Services, you consent to the collection, use, and disclosure of your personal information as described in this Privacy Policy. If you do not agree with any terms of this policy, please do not access or use our Services.

We do not sell, rent, or trade your personal information to any third party for their independent marketing purposes. Full stop.

This Policy should be read alongside our Terms of Service, which governs your use of the platform.

02

Information We Collect

We collect various types of information to provide and improve our Services:

ACCOUNT & IDENTITY DATA
  • Full name and contact details (email address, phone number, physical address)
  • Company name, size, industry, and job title
  • Billing details and invoice history
  • Profile details and avatars (if uploaded)
  • Authentication credentials (passwords are hashed — never stored in plain text)
USAGE & PRODUCT DATA
  • Device and browser specs (IP address, operating system, browser type, device type)
  • Log data (features accessed, pages visited, timestamps, navigation history)
  • API calls, command execution times, and data input summaries
  • Crash reports, error logs, and support ticket descriptions
  • Feedback, survey responses, and customer support communications
THIRD-PARTY DATA INTEGRATION

If you connect third-party integrations, we may receive:

  • Directory details (active directory, Okta, or G Suite profiles)
  • Database sync metrics (record counts, table schemas, and replication timestamps)
  • OAuth authentication tokens for connecting services (e.g. AWS, Github, Slack)
03

How We Use Your Data

PURPOSELEGAL BASISEXAMPLES
Provide & improve the ServicesContract / Legitimate InterestDeliver features, fix bugs, run infrastructure
Account managementContractAuthentication, billing, subscription changes
Customer supportContract / Legitimate InterestAnswer queries, troubleshoot issues
CommunicationsConsent / Legitimate InterestProduct updates, security alerts, newsletters
Analytics & product researchLegitimate InterestUsage trends, A/B testing, roadmap planning
Legal & complianceLegal ObligationTax records, fraud prevention, regulatory requests
Security & abuse preventionLegitimate InterestIntrusion detection, rate limiting, fraud alerts
Marketing (with your consent)ConsentCase studies, events, targeted campaigns
You may withdraw consent for marketing communications at any time via the unsubscribe link in any email or via your account Settings → Notifications.
04

Data Sharing & Disclosure

We share your personal information only in the following specific circumstances:

CATEGORYDETAILS
Service ProvidersCloud hosting (e.g. AWS), payment gateways (e.g. Stripe, Paystack), and email services (e.g. SendGrid)
Business AffiliatesInternal subsidiaries under common corporate control
Legal ComplianceTo respond to valid court orders, subpoenas, or regulatory audits
Business TransfersIn connection with a merger, sale of assets, or corporate acquisition
05

Data Retention

We retain your personal information for as long as your account remains active or as needed to provide you with the Services:

  • Account metadata and profile details are retained for the lifetime of your account.
  • Usage logs and product telemetry data are archived after 90 days and deleted after 365 days.
  • Financial and billing records are stored for 7 years to comply with statutory tax audits.
  • Inactive accounts are subject to deletion after 18 consecutive months of inactivity.
06

Security

Spotless implements a defence-in-depth security programme commensurate with the sensitivity of the data we process. Key measures include:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access control (RBAC) with least-privilege enforcement
  • Multi-factor authentication (MFA) for all internal systems
  • Continuous vulnerability scanning and annual penetration testing
  • SOC 2 Type II certification (report available on request under NDA)
  • 24/7 security monitoring and incident response team
  • Employee security training and background checks
No method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee its absolute security. In the event of a breach affecting your rights, we will notify you within 72 hours where required by applicable law.
07

Cookies & Tracking

We use cookies and similar tracking technologies to store your preferences, analyze usage patterns, and secure your session:

COOKIE TYPEDESCRIPTION
Essential CookiesRequired for core authentication and session tracking
Functional CookiesSaves user preferences (e.g. language, dark mode theme)
Analytical CookiesTracks anonymous traffic metrics using tools like Google Analytics

You can manage your cookie preferences through your browser settings or our built-in cookie consent banner.

08

Your Rights

Depending on your jurisdiction, you may have specific rights regarding your personal data:

  • Right to Access: You can request a copy of the personal data we hold about you.
  • Right to Rectification: You can request updates to incorrect or incomplete information.
  • Right to Erasure (Right to be Forgotten): You can request deletion of your account and data.
  • Right to Restriction: You can ask us to temporarily suspend processing of your data.
  • Right to Portability: You can request your data be exported in a structured JSON format.
  • Right to Object: You can object to direct marketing and automated decisions.
09

International Transfers

Your data may be transferred to and processed in countries outside of your home jurisdiction. We ensure appropriate safeguards are implemented:

  • All cross-border transfers comply with Standard Contractual Clauses (SCCs).
  • Data is processed in regional servers (e.g. EU servers for EU citizens) where mandated.
10

Contact

Our Data Protection Officer (DPO) can be contacted for all privacy-related matters:

CHANNELDETAILS
Emailprivacy@spotless.tech
PostSpotless Technologies Ltd, Data Privacy Team, 123 Clerkenwell Road, London EC1R 5AR, UK
Response SLAWithin 30 calendar days of receipt

For general enquiries about our services, visit the Contact page.

We review and update this Privacy Policy periodically. Material changes will be communicated by email to account holders and flagged with a banner on the platform at least 14 days before taking effect.