PRIVACY POLICY
Privacy Policy
Spock is a product of Seleya Labs Inc., a Delaware (USA) corporation (“Seleya”, “we”, “us”; references to “Spock” as an entity mean Seleya). This policy explains how we collect, use, disclose, and store personal information when you visit our website, create an account, or use the Spock service (the “Service”). It applies together with our Terms of Service and, for business and enterprise customers, our Data Processing Agreement.
1. Who we are and our roles
- For account, billing, telemetry, and support data, Seleya is the data controller / responsible party.
- For Customer Content (your prompts, chats, files, connected data, and outputs), the customer is the controller and Seleya is the processor / operator, acting on the customer’s instructions under the DPA. If you use Spock through your employer’s workspace, your employer is the controller of that content and this policy applies alongside their own policies.
We serve three types of customers: consumers (individual plans), businesses (self-serve team plans), and enterprise (managed engagements under separately signed agreements). Processing is the same across tiers except where this policy says otherwise.
2. Where your data lives and where it is processed
| Data flow | Location |
|---|---|
| Core storage — accounts, workspaces, files, chats, memory | EU (Germany) — Hetzner and DigitalOcean data centres |
| Spock model inference and embeddings (our self-hosted models) | EU — Spock-managed infrastructure |
| Third-party AI inference (OpenAI, Anthropic, Google, xAI, Fireworks AI) | United States (xAI traffic is routed via a Spock-operated US relay) |
| Code execution sandbox (Daytona) | EU |
| Payments (Stripe), web search (Serper), support tooling (Slack) | US / global |
If you or your workspace select the Spock model, your prompts and content are processed entirely on Spock-managed EU infrastructure and do not leave the EU for inference. If you select a third-party model, your prompts and any content you provide in that conversation are transmitted to the relevant US provider for processing.
3. Information we collect
- Account and profile data — name, email address, company, password hash, authentication tokens, sign-in identifiers from Google, Microsoft, or Apple if you use social sign-in.
- Workspace data — team and space names, membership and roles, connected integrations, settings.
- Customer Content — prompts, chats, uploaded files, voice notes, images, data retrieved from integrations you connect, agent and automation outputs, and documents the Service creates for you.
- Memory and personalisation data — a profile the Service builds from your usage (for example your role, preferences, and recurring topics) to personalise responses. You can view, edit, and delete this in Settings at any time. See section 7.
- Usage and telemetry data — logs, device and browser information, IP address, timestamps, feature usage, and error reports.
- Payment and billing data — billing contact, company name, VAT number, subscription tier, and usage/credit consumption. Card details are collected and held by Stripe, not by us.
- Support and feedback data — messages you send to support, responses you report, and incident correspondence.
- Channel data — if you connect the WhatsApp channel, your WhatsApp phone number and the messages you exchange with the Service over WhatsApp.
We do not knowingly collect information from children, and the Service is not directed at them.
4. How we use information
- Provide the Service — accounts, authentication, routing your requests to the AI model you or your workspace selected, running the tools you invoke (web search, file processing, code execution, integrations, automations).
- Process Customer Content on the customer’s instructions under the DPA.
- Personalise the Service — maintain your memory profile (section 7).
- Secure and monitor the Service — logging, abuse and fraud prevention, incident investigation.
- Bill and administer subscriptions via Stripe.
- Communicate with you — service messages, and product updates where permitted.
- Comply with law — POPIA, GDPR, tax and accounting obligations, and lawful requests from authorities.
- Improve the product — using aggregated or de-identified telemetry only.
We never use Customer Content to train, fine-tune, or improve any AI model, and we contractually prohibit our AI sub-processors from doing so. This is a non-derogable commitment; see the DPA.
5. Legal bases
GDPR (EU/EEA/UK users): performance of a contract (Art. 6(1)(b)) for providing the Service; legitimate interests (Art. 6(1)(f)) for security, abuse prevention, product improvement, and routing to AI sub-processors; legal obligation (Art. 6(1)(c)); consent (Art. 6(1)(a)) for marketing communications only.
POPIA (South African users and customers): processing necessary for the conclusion or performance of a contract (s. 11(1)(b)); legitimate interests (s. 11(1)(f)). Where South African customers transfer personal information to Seleya (a foreign operator), the DPA constitutes a binding agreement providing an adequate level of protection under s. 72(1)(b), and we support our South African customers’ own POPIA obligations.
Where you upload personal information about other people (employees, clients, contacts), you must have your own lawful basis to do so.
6. AI processing and automated decision-making
The Service generates content using large language models. Outputs are probabilistic and can be inaccurate; the Terms of Service prohibit using the Service to make legally or similarly significant automated decisions about individuals without meaningful human review. Spock does not itself make automated decisions with legal or similarly significant effect about you.
For details of which models we use, our no-training commitments, and how autonomous features (automations, scheduled agents) are controlled, see our AI Policy.
7. Memory and personalisation (profiling)
Spock maintains a lightweight memory profile derived from your conversations and usage so that responses can reflect your context and preferences. This constitutes profiling under the GDPR. It is used only to personalise your own experience — never for advertising, and never shared with third parties beyond the AI providers that process your requests. You can view, edit, or delete your memory profile in Settings, and deleting it removes it from future processing. You may object to this processing at any time (section 11).
8. Special categories of personal information
We discourage uploading special-category data (health, religious beliefs, trade-union membership, biometric data, data about children). If you upload it anyway, you warrant that you have a lawful basis (such as explicit consent or a statutory ground), that any Prior Authorisation required from the South African Information Regulator has been obtained, and you acknowledge that — unless you use the Spock model — such content is transmitted to US-based AI providers for processing.
9. Sub-processors and recipients
The current list, with locations and purposes, is maintained on our Trust Center and incorporated into the DPA as Annex B. In summary:
- AI inference (US): OpenAI; Anthropic; Google (Gemini / Vertex AI); xAI; Fireworks AI. Each is contractually prohibited from training on your data and retains inputs only transiently (up to 30 days) for abuse monitoring per their API terms.
- AI inference (EU): the Spock model runs on Spock-managed EU infrastructure — no third party involved.
- Hosting (EU/Germany): Hetzner; DigitalOcean.
- Code execution (EU): Daytona — when you run Python code or data analysis, the relevant input files are transferred to an isolated sandbox for execution.
- Web tools: Serper (search queries you or the agent issue); ZenRows S.L., Spain (retrieval of web pages you or the agent request — EU provider).
- Messaging: Meta Platforms (WhatsApp Business Platform) — only if you connect the WhatsApp channel. Note that WhatsApp messages to Spock are processed by Meta’s Business API and are not end-to-end encrypted to Spock.
- Email delivery: Cloudflare (transactional email from mail.spock.chat).
- Payments: Stripe.
- Support and operations: Slack — support requests you submit, responses you report, and system error alerts are relayed to our internal Slack workspace, including your email address, workspace names, and the text you submit.
- Corporate group: account, billing, and commercial contact data may be shared within our corporate group — Seleya Labs Inc. and its wholly-owned South African subsidiary TTL Technologies (Pty) Ltd, which acts as reseller for Spock Enterprise in South Africa. TTL does not access Customer Content.
- Professional advisers and authorities as required, under confidentiality or legal obligation.
Connected apps you choose (MCP and integrations): when you connect a third-party app (for example Notion, HubSpot, Zoho, or another MCP server) and instruct Spock to use it, data flows to and from that service at your direction under your own account with that provider. Those providers are not our sub-processors; their own terms and privacy policies govern. We store the access tokens you grant us, encrypted, and use them only to perform the actions you request.
Workspace integrations (Google Workspace / Microsoft 365 / Slack): Spock’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through these integrations is used only to provide the features you request, is never used for advertising, and is never used to train AI models. Continuous background synchronisation of workspace sources is available only to enterprise customers under a separately signed agreement.
10. Security and retention
Security measures include encryption in transit (TLS 1.3), encryption at rest, EU hosting for core data, least-privilege access controls, logging, and vendor DPAs/SCCs with every sub-processor. Details are on the Trust Center. No system is perfectly secure; we notify affected customers of personal-data breaches without undue delay, and in any event within 72 hours of becoming aware.
Retention:
| Data | Retention |
|---|---|
| Account and workspace data | Duration of the account, then deletion within 12 months of closure |
| Customer Content | Until you delete it or your account closes (then as above) |
| Memory profile | Until you delete it or your account closes |
| Third-party AI provider inference logs | Up to 30 days at the provider, per their API terms |
| Application and security logs | 90–180 days |
| Billing and tax records | As required by applicable law |
| Backups | Rolling deletion cycle |
11. Your rights
GDPR: access, rectification, erasure, restriction, portability, objection (including to profiling under section 7), and the right to complain to your supervisory authority.
POPIA: the rights to be informed, of access, to correction and deletion, to object, to complain to the Information Regulator, and to institute civil proceedings.
To exercise any right, contact support@spock.chat. We respond within one month (GDPR) or as prescribed by POPIA. You can also delete your account yourself in Settings, which triggers deletion of your data per the retention table above. If you interact with Spock as an end-user of one of our business or enterprise customers, we may forward your request to that customer as the responsible controller.
12. International transfers
Transfers from the EU to the US (third-party AI providers, Stripe, Serper, Slack) are protected by the European Commission’s Standard Contractual Clauses (2021/914) entered into with each vendor, supplemented by the measures described in our Transfer Impact Assessments on the Trust Center. Although Seleya is a US-incorporated company, your data is hosted in the EU; remote administrative access by our personnel is limited, logged, and subject to the safeguards in the DPA. Transfers from South Africa rely on s. 72(1)(b) POPIA (binding agreements providing adequate protection). If you use only the Spock model, your Customer Content is not transferred outside the EU for inference.
13. Cookies
The Service and website use strictly necessary cookies only (authentication, session, security). We do not use analytics, advertising, or third-party tracking cookies, and consequently there is nothing to opt out of. We treat Global Privacy Control and Do Not Track signals as satisfied by default.
14. Children
The Service is intended for users aged 18 or over. We do not knowingly collect children’s data and will delete it if discovered.
15. Changes to this policy
We may update this policy when the Service, our vendors, or the law changes. Material changes will be notified through the Service or by email before they take effect. Prior versions are available on request.
16. Contact and complaints
Controller: Seleya Labs Inc. (Delaware, USA) — support@spock.chat
Privacy contact: Louis-Neil Korsten, CEO — louis@spock.chat
South African Information Regulator: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 — complaints.IR@justice.gov.za / inforeg@justice.gov.za
EU and UK data subjects may direct privacy enquiries to support@spock.chat and retain the right to complain to their local supervisory authority.