TRUST CENTER
Trust Center
Our commitments
- Your data never trains AI models. Not ours, not anyone’s. This is a contractual, non-derogable obligation with a refund remedy (DPA §8).
- EU data residency for storage — and EU-only inference if you want it. All core data lives in Germany. Choose the Spock model and your prompts never leave EU infrastructure.
- Transparent data flows. Every provider that touches your data is listed below, with location and purpose.
- GDPR and POPIA alignment, with a comprehensive DPA available to every business and enterprise customer.
Where your data lives
| Processing | Location |
|---|---|
| Storage (accounts, files, chats, memory) | 🇩🇪 Germany — Hetzner, DigitalOcean |
| Spock model inference + embeddings (self-hosted) | 🇪🇺 EU — Spock-managed infrastructure |
| Code execution sandbox (Daytona) | 🇪🇺 EU |
| Web page retrieval (ZenRows) | 🇪🇺 EU (Spain) |
| Third-party AI inference (OpenAI, Anthropic, Google, xAI, Fireworks) | 🇺🇸 US — only when you select those models; protected by SCCs |
| Payments (Stripe), web search (Serper), support tooling (Slack) | 🇺🇸 US / global — SCCs |
Keeping your data in the EU: select the Spock model and your prompts and content are processed entirely on Spock-managed EU infrastructure — no US transfer occurs for inference.
Security measures
- Encryption: TLS 1.3 for all data in transit; encryption at rest for stored core data; passwords stored as salted hashes only.
- Access control: least-privilege, role-based access; access logging.
- Network: EU hosting, environment segregation, SSRF protections on server-side web fetching.
- Development: code review, CI test gates, migration rehearsal against production snapshots before every deploy.
- Agent safety: tool-call approval gates for sensitive actions; sandboxed code execution; prompt-injection defences on web content ingestion.
- Incident response: documented procedure; customer notification without undue delay and within 72 hours.
Retention at a glance
| Data | Retention |
|---|---|
| Your content | Until you delete it / account closure + ≤12 months |
| Memory profile | Until you delete it (self-serve in Settings) |
| Third-party AI provider logs | ≤30 days at the provider (never used for training) |
| Application/security logs | 90–180 days |
| Backups | Rolling deletion |
Sub-processors
This is the authoritative list referenced by the DPA (Annex B). Changes are announced here and by email to workspace admins 14 days in advance.
| Sub-processor | Location | Purpose | Safeguard |
|---|---|---|---|
| OpenAI, L.L.C. | US | AI inference (when an OpenAI model is selected) | DPA + SCCs; no training; ≤30-day retention |
| Anthropic, PBC | US | AI inference (when an Anthropic model is selected) | DPA + SCCs; no training; ≤30-day retention |
| Google LLC (Gemini API / Vertex AI) | US | AI inference; image generation; voice-note transcription | DPA + SCCs; no training; ≤30-day retention |
| xAI Corp. | US | AI inference (when an xAI model is selected); traffic routed via a Spock-operated US relay | DPA + SCCs; no training; ≤30-day retention |
| Fireworks AI, Inc. | US | Hosted open-source model inference | DPA + SCCs; no training; ≤30-day retention |
| Hetzner Online GmbH | Germany | Hosting of core data | DPA; EU processing |
| DigitalOcean LLC | Germany (region) | Hosting of core data | DPA + SCCs; EU region |
| Daytona | EU | Sandboxed code execution; input files transferred per run | DPA; EU processing |
| Serper | Global (treated as a third-country transfer) | Web search queries | DPA + SCCs |
| ZenRows S.L. | Spain (EU) | Web page retrieval on user request | DPA |
| Meta Platforms (WhatsApp Business Platform) | US/global | WhatsApp channel messaging (only when connected) | Meta Business terms + SCCs |
| Cloudflare, Inc. | US/global (EU delivery) | Transactional email (mail.spock.chat) | DPA + SCCs |
| Stripe, Inc. | US/global | Payment processing (independent controller for card data) | DPA + SCCs |
| Slack Technologies (Salesforce) | US | Internal support and incident alerting (support requests, response reports, error alerts: identifiers, workspace names, submitted text) | DPA + SCCs |
Not sub-processors: the Spock model and embeddings (self-hosted on Spock-managed EU infrastructure); OCR (self-hosted); third-party apps and MCP servers you connect under your own accounts.
Changelog
- 1 August 2026, v2.0 — Added: xAI, Fireworks AI, Google Vertex AI, Daytona (EU), Serper, ZenRows (EU), Meta (WhatsApp), Cloudflare (email), Slack (support tooling). Removed: Groq, Resend, Crisp.
Compliance
- GDPR — DPA with SCCs (2021/914), UK Addendum, and Swiss adaptation available to all business/enterprise customers.
- POPIA — s. 72(1)(b) transfer support for South African customers (the DPA is a binding agreement providing adequate protection); protections extended to juristic persons in the DPA.
- SOC 2 Type II — our audit program commences late 2026. Until our own report is issued, we rely on and can share the certifications of our infrastructure providers (Hetzner: ISO 27001; DigitalOcean: SOC 2 Type II, ISO 27001; Stripe: PCI-DSS Level 1).
- Transfer Impact Assessments — our assessment of US transfers is published here.
AI transparency
See the AI Policy for the models we route to, our no-training guarantees, retention at each provider, and how autonomous agents are controlled.
Vulnerability disclosure
We welcome good-faith security research. Report vulnerabilities to security@spock.chat. We acknowledge reports within 3 business days, will not pursue legal action for good-faith research that respects user privacy and service availability, and will credit researchers who wish it. Our disclosure contact is also published at /.well-known/security.txt.
Incidents
We have had no reportable personal-data breaches to date. Affected customers are notified of any personal-data breach without undue delay, and in any event within 72 hours.
Contact
Spock is a product of Seleya Labs Inc. (Delaware, USA).
Security: security@spock.chat · Privacy: support@spock.chat · Privacy officer: louis@spock.chat