Spyral — Privacy Policy (EU/EEA)
Version 2.0.0 | Last updated: 9 September 2026
This Privacy Policy explains how Spyral (“Spyral”, “we”, “us”) collects, uses, discloses and protects personal data when providing the Spyral platform for document intelligence, annual accounts and bookkeeping workflows, and related services to professional firms.
This English version is the authoritative text. Any translation is provided for convenience only; in case of conflict, the English version prevails.
Who We Are and How to Contact Us
Spyral operates a cloud-based, multi-tenant platform used by professional firms to organise, analyse and file documents. Our services are directed at business customers in the EU/EEA, with a focus on Luxembourg and the wider Benelux region.
Privacy and Data Protection Contacts
- Privacy and data protection: privacy@spyral.lu
- General enquiries: contact@spyral.lu
- Security incidents: security@spyral.lu
We have not appointed a Data Protection Officer, as we are not required to do so under GDPR Article 37. Privacy enquiries are handled through the contacts above.
Right to Lodge a Complaint
Under GDPR Article 77, you may lodge a complaint with the supervisory authority in the EU/EEA Member State of your habitual residence, your place of work, or the place of the alleged infringement. In Luxembourg this is the Commission nationale pour la protection des données (cnpd.public.lu). We would appreciate the opportunity to address your concern first, at privacy@spyral.lu.
Scope and Role Under GDPR
This Privacy Policy applies to:
- Visitors to www.spyral.lu and related websites
- Representatives, employees, contractors and end-users of Spyral's business customers who access the platform
- Individuals who contact us by email or through support channels, or whose personal data we process in connection with our services
Spyral's Role Under GDPR
- As Data Processor:For customer content processed through the platform — the documents a firm uploads or connects, and everything derived from them — Spyral acts as a processor on the documented instructions of the customer firm, which is the controller.
- As Data Controller: For account administration, billing, service communications, support records, website operation, security monitoring and marketing to business contacts, Spyral acts as an independent controller.
Where Spyral acts as processor, the customer firm decides what is uploaded, who may access it, and how long it is kept. Requests from individuals about that content are directed to the firm.
Categories of Personal Data Processed
1. Account and Identification Data
- Name, business email address, and where provided, job title and firm details
- Authentication data: a hashed password, and where two-factor authentication is enabled, an encrypted TOTP secret
- Team membership, assigned roles and permissions, and project memberships
- User profile preferences, interface settings and notification preferences
- Optional profile picture
2. Usage, Session and Log Data
- Sign-in times, session identifiers, IP address, user-agent string and language preference
- Activity records of security-relevant and administrative actions — sign-in and sign-out, password and two-factor changes, role and permission changes, invitations, data export, and deletion of documents, companies and projects — each recorded with the acting user, IP address and user-agent
- Search queries run against the firm's own content, and saved searches and bookmarks
- Error records used to diagnose failures, each identified by a reference code that support can look up
- Usage counters for AI operations, recorded for billing and for enforcing rate limits
3. Customer Content
- Documents uploaded or connected by the customer firm, and the text extracted from them, including text recovered from scanned documents by optical character recognition
- Such documents routinely contain personal data about the firm's employees, contractors, clients and third parties — including directors, shareholders and beneficial owners named in corporate and financial records
- Data derived from documents by automated processing: classifications, extracted attributes, entries in the firm's company and person directories, ownership relationships, bookkeeping entries, and numerical representations of document text used to power search
- Chat conversations with the platform's assistant, including the questions asked and the answers returned
- Corrections a reviewer makes to automated output, retained so the platform can apply the firm's own conventions to later documents
4. Data from Connected Services
Customers may connect third-party services they already use. Each connection is initiated by the customer, is optional, and can be disconnected at any time. Where a connection is active, we process:
- Google Drive: only the specific files a user selects through the Google file picker, together with their file name, type, size and dates. See the dedicated section below.
- Dropbox: the contents and metadata of files in the folders a customer designates for synchronisation.
- Electronic signature: signer names and email addresses supplied by the customer, and the status and audit events of signature requests sent on the customer's behalf.
- Workspace messaging: where a customer links a workspace messaging tool, the identifiers needed to route commands and notifications, and the text of commands issued to Spyral from that tool.
Access credentials for connected services are encrypted before storage and are invalidated and deleted when the connection is removed.
5. Support and Communication Data
- The content of support requests and our correspondence with you
- Records of issues raised and resolutions provided
6. Website Data
- Standard server and security logs for www.spyral.lu
- Contact details submitted through waitlist or enquiry forms
7. Product Analytics (Trial Teams, Consent-Based)
During a trial, and only after the team has given consent in the application, we collect pseudonymised product analytics: which features were used, session duration, and whether an action succeeded or failed. The team identifier is stored only as a keyed hash, and no document content, file names, prompts, AI responses or form entries are collected. These records are deleted automatically 90 days after collection, and collection stops when the team moves to a paid subscription. Consent can be withheld or withdrawn without any loss of functionality. See Data Processing — Trial Analytics.
Special Categories of Personal Data
The platform is not designed for special category data under GDPR Article 9 (such as health data, biometric data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, or data concerning sex life or sexual orientation), nor for criminal conviction data under Article 10. Customers are contractually instructed not to upload such data unless they have their own lawful basis and have agreed the necessary measures with us in writing. Because customers control what they upload, we cannot prevent such data appearing in a document; where it does, it is protected by the same access controls and security measures as all other customer content.
Google API Services — Data Collection, Use and Disclosure
How the Google Drive Integration Works
Spyral does not connect to a customer's Google Drive account in the background and does not browse or index a Drive. Instead, a user opens the Google file picker inside Spyral and selects specific files. Google grants Spyral access to those individual files only, for the purpose of importing them.
Google API Scope Requested
- https://www.googleapis.com/auth/drive.file— a per-file scope that grants access only to files the user has explicitly selected or that were created by Spyral. It does not permit access to any other file in the user's Drive.
This is the narrowest scope that supports the feature. Spyral does not request broad Drive read access, does not request Gmail or calendar access, and does not request any scope that Google classifies as restricted.
How Spyral Uses Google Drive Data
Files imported through the Google file picker are treated exactly like uploaded files and are used only to:
- Extract text and make the document searchable within the customer's own workspace
- Classify the document and extract its attributes
- Link it to the companies and people it refers to, within the customer's own directories
- Provide grounded, cited answers when a user asks a question about their own documents
- Feed the customer's bookkeeping and annual accounts workflows
Google API Services User Data Policy Compliance
Spyral's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Limited Use Requirements
- Limited to user-facing features: Google user data is used only to provide the user-facing features described above.
- No unauthorised transfers: Google user data is not transferred to third parties except as necessary to provide those features, for security purposes, to comply with applicable law, or as part of a merger or acquisition with prior user notice.
- No human access without consent: Personnel do not read Google user data unless the user has specifically asked us to look at particular content, it is necessary to investigate abuse or a security incident, or it is required by law.
- Binding on all parties: Employees, contractors and successors are bound by these requirements.
Explicit Prohibitions Regarding Google User Data
Spyral does not:
- Sell Google user data
- Use Google user data for advertising of any kind, including retargeting or interest-based advertising
- Use Google user data to determine credit-worthiness or for lending purposes
- Provide Google user data to data brokers or information resellers
- Use Google user data to train or fine-tune any AI or machine learning model
Disconnecting Google Drive
Because access is granted per file at the moment of import, there is no standing background connection to revoke. Users may nevertheless review and remove any Spyral authorisation at myaccount.google.com/permissions. Files already imported into the workspace remain there as customer content and can be deleted from within Spyral like any other document, or by request to privacy@spyral.lu.
Purposes and Legal Bases
We process personal data only for specified, explicit and legitimate purposes, and do not further process them in a manner incompatible with those purposes (GDPR Article 5(1)(b)).
1. Providing the Platform (Processor Role)
Purpose: Operating the platform on the customer's instructions — document ingestion and text extraction, classification, search and question answering over the firm's own content, company and person directories, bookkeeping, annual accounts preparation and filing support, collaboration and document editing.
Legal basis: The customer firm determines the legal basis as controller. Spyral processes under Article 28 on documented instructions, pursuant to the service contract and the Data Processing Agreement.
2. Account Management, Access Control and Security
Purpose: Creating and administering accounts, enforcing tenant isolation and role-based permissions, operating two-factor authentication and session management, rate limiting, and detecting and responding to abuse and security incidents.
Legal basis: Performance of the contract (Article 6(1)(b)); legitimate interests in the secure operation of the service and in network and information security (Article 6(1)(f), read with Recital 49).
3. Billing and Subscription Administration
Purpose: Processing subscription payments, maintaining seat counts, issuing invoices and meeting accounting obligations.
Legal basis: Performance of the contract (Article 6(1)(b)); compliance with legal obligations in tax and accounting law (Article 6(1)(c)).
4. Support, Incident Handling and Service Communications
Purpose: Answering support requests, sending security alerts, service announcements and material change notices.
Legal basis: Performance of the contract (Article 6(1)(b)); legitimate interests in supporting and informing our customers (Article 6(1)(f)).
5. Product Analytics During Trials
Purpose: Understanding which features trial teams use and where they encounter friction, in pseudonymised form.
Legal basis: Consent (Article 6(1)(a)), given by the team in the application and withdrawable at any time without any loss of functionality.
6. Sales, Marketing and Business Development
Purpose: Communicating with business contacts about demonstrations, trials and product developments.
Legal basis: Consent where required by the ePrivacy rules on electronic marketing; otherwise legitimate interests in promoting our services to business contacts (Article 6(1)(f)), balanced against their reasonable expectations.
Opt-out: Every marketing email carries an unsubscribe link, and you may object at any time by writing to privacy@spyral.lu.
7. Legal, Compliance and Dispute Handling
Purpose: Meeting legal and regulatory obligations, responding to lawful requests from authorities, handling disputes, and demonstrating accountability under GDPR Article 5(2).
Legal basis: Compliance with legal obligations (Article 6(1)(c)); legitimate interests in establishing, exercising or defending legal claims (Article 6(1)(f)).
Where we rely on legitimate interests, we have carried out a balancing assessment and will provide a summary on request. You may object to such processing under Article 21.
Tenant Isolation and Access Control
Each customer firm occupies its own logical tenant. Isolation is enforced at two independent layers, so that a single mistake at one layer does not expose data:
- Application layer: Every request is authenticated, checked against the acting user's permissions, and scoped to their tenant before any data is read.
- Database layer: The database independently enforces tenant boundaries under a least-privilege service account. A query that fails to identify its tenant returns no rows rather than another tenant's rows — it fails closed.
- Automated verification: Both layers are checked automatically before any change reaches production. A change that would introduce a query without a tenant boundary cannot be released.
Within a firm, access is further restricted by role and by document visibility, which the firm's administrators configure. Documents can be made available to the whole firm, to a project team, to a restricted group, or to named individuals. Permissions are default-deny: a user receives only what their role grants.
We describe these controls in terms of what they guarantee rather than how they are built. No security architecture is infallible, and we make no claim that breach is impossible. Details sufficient for a security review are available to customers under a confidentiality agreement.
Access by Spyral Personnel
Spyral personnel do not access customer content in the ordinary course of operating the service. Access occurs only where:
- The customer asks us to investigate a specific problem
- It is necessary to respond to a security incident
- It is required by law or by a valid order from a competent authority
Such access is limited to what is strictly necessary and is performed by named personnel bound by confidentiality obligations. User actions in the application are logged, and the administrative access paths used for maintenance are restricted and enumerated. Customers subject to professional secrecy obligations can ask us to agree in writing that any such access happens only under their supervision.
AI Processing, Retrieval and Transparency
How AI Features Work
Spyral uses large language models, embedding models and vision models to read documents, classify them, extract structured information and answer questions. These models are operated by a specialist AI infrastructure provider engaged by Spyral as a sub-processor and bound by a Data Processing Agreement. Spyral does not develop foundation models of its own.
When a user asks a question, the sequence is:
- Retrieval: The platform searches only within the asking user's own tenant, and only across documents that user is permitted to see, to find the passages most relevant to the question.
- Generation: Those passages and the question are sent to the model, which produces an answer grounded in them.
- Citation: The answer is returned with links to the source documents so the user can verify it.
Safeguards
1. No training on customer data
Customer content, prompts and generated outputs are never used to train, fine-tune or otherwise improve any AI model, whether ours or a provider's. This is a contractual requirement on our AI sub-processor, and retention at the provider is governed by the same contract.
2. EU processing
AI inference for the production service is performed on infrastructure located in the European Union. Should this ever change, the International Data Transfers section below governs, and we will notify customers in advance.
3. Tenant-scoped context
Only content from the requesting user's own tenant, filtered by that user's permissions, is included in a model request. Content is never combined across customer firms.
4. No automated decisions with legal effect
Spyral does not make decisions producing legal effects concerning individuals, or similarly significantly affecting them, based solely on automated processing within the meaning of GDPR Article 22. Classifications, extractions and draft filings are proposals presented for human review; a person decides whether to accept them, and low-confidence output is flagged for review.
Transparency under the EU AI Act
Spyral's AI features are not high-risk AI systems under Regulation (EU) 2024/1689 (the AI Act), and Spyral does not engage in any practice prohibited under Article 5. On transparency:
- Surfaces where you interact with an AI system are presented as such, and carry a notice at the point of use that responses may be inaccurate and should be verified.
- AI output is labelled in the interface and carries citations to the source documents it was drawn from, so that any assertion can be traced back and checked.
We document what each AI feature does, what it is suitable for, and where human review is required. That documentation supports a customer's own obligations under the AI Act; it does not discharge them.
Limitations of AI Output
AI output can be incomplete, out of date or wrong. It must not be relied on without independent verification, and human oversight is required for anything used in a filing, a client deliverable or a decision with consequences. Spyral provides tools that make verification practical — citations, confidence flags and review queues — but the professional judgement remains the user's.
Data Sharing and Sub-Processors
Spyral does not sell personal data and does not share it for advertising. Personal data is shared only with the following categories of recipients, and only to the extent necessary:
Categories of Sub-Processor
- Cloud hosting and application delivery — running the application and serving requests
- Managed database and object storage — storing documents and structured data
- AI inference infrastructure — running the language, embedding and vision models described above
- Transactional email delivery — sending invitations, verification codes and notifications
- Payment processing — handling subscription payments; Spyral does not receive or store full card details
- Error monitoring and infrastructure services — diagnosing faults and enforcing rate limits
- Electronic signature — only where the customer uses the signature workflow
Every sub-processor is engaged under a written contract meeting GDPR Article 28(3), is bound to confidentiality and to security measures no less protective than our own, and is assessed before we engage it.
Current list.A current list of sub-processors, giving each one's name, role, and processing location, is maintained and provided to customers and prospective customers on request to privacy@spyral.lu. Customers are notified in advance of any intended addition or replacement of a sub-processor and may object on reasonable data protection grounds, as set out in the Data Processing Agreement.
Professional Advisers
External auditors, legal counsel and security testers may access data where necessary for their engagement. All are bound by confidentiality obligations.
Authorities and Legal Disclosure
- We disclose personal data to authorities only where required by law or by a valid, binding order
- We assess each request for legality and proportionality and challenge those that are overbroad or invalid
- Where legally permitted, we notify the affected customer before disclosing
- We disclose only the minimum data necessary to comply
- We do not grant any government direct or unsupervised access to customer data, and we have not built any facility for such access
International Data Transfers
EU processing by default. Customer content is hosted and processed within the European Union, and AI inference for the production service is performed on EU infrastructure. Customer content is not routinely transferred outside the EEA.
Where a transfer occurs.A limited number of operational functions — for example support correspondence or error diagnostics — may involve access from, or storage in, a country outside the EEA. Where that happens we rely on an adequacy decision under GDPR Article 45 where one is available, and otherwise on the European Commission's Standard Contractual Clauses under Article 46, supported by a transfer impact assessment and by supplementary technical and organisational measures where the assessment calls for them.
Customers may ask which transfer mechanism applies to any specific sub-processor at privacy@spyral.lu.
Security Measures
We implement technical and organisational measures appropriate to the risk, as required by GDPR Article 32. These include the following.
Encryption
- In transit: All traffic between users, the platform and third-party services is encrypted with current TLS. HTTP Strict Transport Security is enforced.
- At rest: Databases and object storage are encrypted at rest by our infrastructure providers using AES-256.
- Application-level encryption for secrets: Two-factor authentication secrets and third-party access tokens are additionally encrypted with AES-256-GCM under dedicated keys before storage, so that they remain protected independently of storage-layer encryption.
Authentication and Access Control
- Passwords are hashed with bcrypt and per-user salts; plaintext passwords are never stored or logged
- Optional two-factor authentication using time-based one-time passwords (TOTP)
- Sessions are held in cookies that are HTTP-only, Secure and same-site restricted, with a limited lifetime
- Users can review active sessions and sign out of all devices; changing a password or signing out everywhere invalidates existing sessions immediately
- Attribute-based permissions with default-deny, enforced on every request
Application Security
- Cross-site request forgery protection on all state-changing requests
- A content security policy, clickjacking protection, MIME-sniffing protection and a restrictive permissions policy on all responses
- All input validated against strict schemas at every boundary
- Rate limiting on authentication, upload and AI endpoints, with the cost-sensitive limits failing closed
- Uploaded files validated by content, not only by file extension
- Error responses carry a reference code rather than internal detail, so that diagnostics never leak system information to a user or an attacker
Monitoring and Audit
- Security-relevant actions are recorded with the acting user, IP address, user-agent and timestamp
- Errors and anomalies are monitored continuously with automated alerting
- Administrative and cross-tenant operational access paths are restricted and enumerated, and any change to them is checked automatically before release
Security Assurance
On request, and under a confidentiality agreement, we provide customers with a description of our technical and organisational measures sufficient to complete a vendor security assessment, and we make available the information needed to demonstrate compliance with our processor obligations, as GDPR Article 28(3)(h) requires.
Data Retention and Deletion
Retention is limited to what is necessary for the purposes described above and for compliance with legal obligations. The periods below are the ones we actually operate.
Customer Content
- Retained for as long as the customer keeps it and the subscription is in force. The customer controls deletion.
- When a document is deleted in the application, the stored file and the data derived from it are removed from the live service. Copies may persist in our infrastructure providers' encrypted backups until those expire on their schedule, which we do not set. Backups are not restored to the live service to recover deleted content.
- On termination, customer content is retained for at least 30 days so you can retrieve it, and is deleted from the live service within 90 days of termination. Backup expiry follows our infrastructure providers' own schedules, which we do not control and therefore do not put a date on.
User Accounts
- Retained while the account is active.
- When a user deletes their account, the account is deactivated immediately, sessions are invalidated, the email address is released, and the user loses all access. A minimal record is retained where necessary to preserve the integrity of the firm's audit trail and to meet our own legal obligations, and is deleted when that necessity ends.
Activity and Audit Records
- Retained for the life of the customer relationship, because they exist to let a firm reconstruct who did what — a requirement several of our customers are themselves subject to. Deleted with the tenant on termination.
Product Analytics
- Deleted automatically 90 days after collection.
Error and Diagnostic Records
- Retained for as long as they remain useful for diagnosis and security analysis, and pruned periodically. Records relating to a specific customer are deleted on request.
Billing and Accounting Records
- Retained for the period required by applicable tax and accounting law, which in Luxembourg is 10 years.
We do not claim instantaneous or forensically irreversible erasure. Deletion removes data from the live service within the periods above; provider backups expire on their own schedules. On request we will confirm in writing once deletion is done.
Your Rights Under the GDPR
- Access (Article 15): Confirmation of whether we process your data, and a copy of it
- Rectification (Article 16): Correction of inaccurate or incomplete data
- Erasure (Article 17): Deletion, where one of the grounds in Article 17(1) applies
- Restriction (Article 18): Restriction of processing while a dispute is resolved
- Portability (Article 20): Receipt of data you provided, in a structured, commonly used, machine-readable format
- Objection (Article 21): Objection to processing based on legitimate interests, and an absolute right to object to direct marketing
- Withdrawal of consent (Article 7(3)): Withdrawal at any time, without affecting processing already carried out
- Automated decision-making (Article 22): As set out above, we do not carry out solely automated decision-making with legal or similarly significant effects
Exercising Your Rights
If your data is in a customer's workspace (we are the processor): contact the firm that holds it. They are the controller and decide the outcome. We assist them promptly, as required by GDPR Article 28(3)(e).
If we are the controller— your account, our correspondence with you, marketing: write to privacy@spyral.lu. We respond within the one month allowed by Article 12(3), and where a request is complex or where we have received a number of them, we extend by up to the two further months that Article also allows, telling you within the first month and explaining why. There is no charge unless a request is manifestly unfounded or excessive.
Self-service: Signed-in users can export their own data as a structured file, review and revoke active sessions, and delete their account, from the account settings page.
Cookies and Similar Technologies
Spyral uses only cookies that are strictly necessary to deliver the service you have requested. Under Article 5(3) of the ePrivacy Directive these are exempt from the consent requirement, which is why you are not asked to accept cookies.
- Session cookie — keeps you signed in. HTTP-only, Secure, same-site restricted.
- Two-factor verification cookie — short-lived, records that a second factor was completed.
- Sign-in state cookies — set during authentication.
- Language cookie — remembers your interface language.
- Connection state cookies — short-lived, protect the integrity of a third-party connection flow you have started.
We do not use advertising cookies, cross-site tracking, third-party analytics scripts or social media pixels on the application. Product analytics for trial teams are collected server-side under in-app consent and do not use cookies. If we ever introduce a non-essential cookie, we will ask for your consent first and will not set it before you agree.
Regulatory Framework We Operate Under
Beyond the GDPR, the following EU rules shape how the platform is built and contracted. We list them so that customers can see how our obligations meet theirs.
ePrivacy Directive (2002/58/EC)
Governs cookies and electronic marketing. We use only strictly necessary cookies and honour opt-outs on all marketing email.
AI Act (Regulation (EU) 2024/1689)
Applicable since 2 August 2026. We use no prohibited practice under Article 5 and operate no high-risk AI system under Annex III. How AI use is disclosed in the product is described in the AI section above.
Data Act (Regulation (EU) 2023/2854)
Chapter VI gives customers of data processing services the right to switch provider effectively, and sets the maximum notice period, the exit obligations and the limits on what may be charged for switching. What we owe you under it is set out in the Terms of Service.
DORA (Regulation (EU) 2022/2554)
Customers that are financial entities must place specific contractual terms on their ICT service providers. These are agreed individually: tell us which regime applies to you and what it requires, and we will agree the terms it calls for.
NIS2 (Directive (EU) 2022/2555)
Customers within scope of NIS2 must manage supply chain security. We provide security documentation on request and notify you of incidents affecting the services you receive. Further measures are agreed in writing.
Luxembourg professional secrecy
Customers subject to professional secrecy — including professionals of the financial sector and members of regulated professions — carry duties that survive outsourcing. Confidentiality obligations on our personnel, prior notification of sub-processor changes, and EU data location apply as standard and are described elsewhere on this page. Where a supervisory outsourcing framework applies to you, tell us which one and what it requires of your providers, and we will agree those terms before you upload data covered by the obligation.
eIDAS (Regulation (EU) No 910/2014, as amended)
Where the platform is used to obtain electronic signatures, the level of signature is determined by the signature service and the customer's configuration. Customers are responsible for confirming that the level obtained satisfies the legal requirements of the filing or transaction concerned.
Children's Data
Spyral is a business tool, is not directed at children, and is not made available to them. We do not knowingly collect personal data from children. If you believe a child's data has reached us, write to privacy@spyral.lu and we will delete it.
Data Processing Agreement and Customer Responsibilities
Every EU/EEA customer enters into a Data Processing Agreement meeting GDPR Article 28(3). It covers subject matter and duration, the nature and purpose of processing, categories of data and data subjects, processing on documented instructions only, confidentiality, security measures, sub-processor authorisation and notification, assistance with data subject rights and with Articles 32 to 36, deletion or return on termination, audit rights, and transfer mechanisms. A copy is available at privacy@spyral.lu.
As controller, the customer firm remains responsible for: having a lawful basis for what it uploads; informing its own data subjects; ensuring accuracy; configuring access correctly within its workspace; carrying out a data protection impact assessment where required; setting its own retention rules; and reviewing AI output before relying on it.
Security Incidents and Breach Notification
We maintain a documented incident response process. Where a personal data breach affects customer data:
- Notification to the customer: without undue delay after becoming aware, which is the standard GDPR Article 33(2) sets
- Information provided: the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, and the measures taken or proposed — provided in phases if not all of it is available at once
- Assistance: we assist the customer in meeting its own notification duties to supervisory authorities under Article 33 and to affected individuals under Article 34, which is what GDPR Article 28(3)(f) requires of us. If your own regime imposes a shorter or parallel reporting duty, tell us and we will agree in writing what we need to do to support it
- Follow-up: a written summary on completion, provided on request
Report a suspected vulnerability or incident to security@spyral.lu. We aim to acknowledge reports within five business days. No guaranteed acknowledgement or remediation window is offered. We do not pursue legal action against researchers who report in good faith, act proportionately, and give us reasonable time to remediate before disclosure.
Third-Party Links and Services
Our websites and the platform may link to third-party services. This Privacy Policy does not apply to them, and we are not responsible for their practices. Where you connect a third-party service to Spyral, that provider's own terms and privacy policy continue to govern your relationship with it.
Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in law, in our practices, or in the service. The version number and date at the top of this page always identify the current text. We give reasonable advance notice of a material change — normally at least 30 days — by email to account administrators and by notice in the application. A change we are required to make by law, or one needed to address a security risk, may take effect sooner. Where a change requires consent, we will ask for it rather than assume it.
Definitions
- Personal data: Any information relating to an identified or identifiable natural person
- Controller: The party that determines the purposes and means of processing
- Processor: The party that processes personal data on behalf of a controller
- Sub-processor: A processor engaged by Spyral to carry out part of the processing
- Customer / firm: A business that subscribes to Spyral
- Tenant: The isolated workspace belonging to one customer firm
- Customer content: Documents and data uploaded, connected or generated by a customer in its tenant
- Pseudonymisation: Processing such that data can no longer be attributed to a specific person without additional information kept separately (GDPR Article 4(5))
- Google user data: Data accessed through Google APIs, being the content and metadata of files a user selects through the Google file picker
Contact
Privacy and data protection: privacy@spyral.lu
Security incidents and vulnerability reports: security@spyral.lu
General enquiries: contact@spyral.lu
Version 2.0.0, last updated 9 September 2026.