Privacy Policy
Last updated 27 September 2026
This policy explains what personal data Spanacle Software Services ("we", "us") collects when you visit spanacle.com, contact us or work with us, why we collect it, and the rights you have over it. We collect as little as we need, and we never sell it.
Who we are
Spanacle Software Services is a software company based in Delhi, working remotely. For personal data collected through this website and our sales process, Spanacle Software Services is the data controller (the "data fiduciary" under Indian law). For data inside systems we build or support for clients, we act as a data processor on the client's instructions (see "Client data" below).
Privacy and grievance contact: contact[at]spanacle.com.
The laws we follow
We work with clients in the EU, the UK, the US, Australia and India, so we apply the data protection laws of each. Where they differ, we follow the stricter standard.
| Region | Law | Where you can complain |
|---|---|---|
| European Union | General Data Protection Regulation (EU) 2016/679 (GDPR) | Your local data protection authority |
| United Kingdom | UK GDPR, the Data Protection Act 2018 and PECR | Information Commissioner's Office (ICO) |
| United States | California Consumer Privacy Act as amended by the CPRA, and other applicable state privacy laws | California Privacy Protection Agency or your state attorney general |
| Australia | Privacy Act 1988 and the Australian Privacy Principles | Office of the Australian Information Commissioner (OAIC) |
| India | Digital Personal Data Protection Act 2023, and the Information Technology Act 2000 and its rules | Data Protection Board of India |
What we collect and why
When you send an enquiry
Your name, work email, company, where you are based, your area of interest and your message. We use these only to reply and to prepare a proposal. Our legal basis is taking steps at your request before entering into a contract, and our legitimate interest in responding to business enquiries (GDPR Article 6(1)(b) and (f)).
When you book a call or message us
Your name, email and the details you add when booking through Calendly, or your phone number and messages if you contact us on WhatsApp or by phone. We use them to hold the call and follow up.
When you become a client
Contact details of your team, contracts, invoices and project correspondence. We use them to deliver the work, bill for it and meet our legal obligations (GDPR Article 6(1)(b) and (c)).
When you browse this website
This website does not use advertising or analytics cookies, does not track you across other sites, and serves its fonts from our own domain. Our hosting provider processes standard technical data, such as IP addresses, to deliver and protect the site. If we ever add analytics or marketing cookies, we will ask for your consent first and update this policy.
We do not collect special-category or sensitive personal data through this website, and we do not make automated decisions about you.
Who we share it with
We never sell or rent personal data, and we do not "share" it for cross-context behavioural advertising as defined under the CCPA. We use a small number of service providers that process data on our behalf, under written contracts that require confidentiality and security:
| Provider | Purpose |
|---|---|
| Email delivery service | Delivers contact-form enquiries to our inbox |
| Cloudflare | Hosts and secures this website |
| Calendly | Schedules discovery calls you book with us |
| WhatsApp (Meta) | Carries messages if you choose to contact us on WhatsApp |
| Email and document tools | Store our correspondence and proposals |
We may also disclose data where the law requires it, or to protect our legal rights.
International transfers
Our team works from India, so personal data from the EU, the UK and Australia is transferred to and accessed from India. Where the law requires a transfer safeguard, we use the European Commission's Standard Contractual Clauses and, for the UK, the International Data Transfer Addendum. We take reasonable steps to make sure overseas recipients handle data in line with the Australian Privacy Principles. You can ask us for a copy of these safeguards.
How long we keep it
- Enquiries that do not become projects: deleted 24 months after our last contact.
- Client contracts and invoices: kept for as long as tax and company law requires, currently up to 8 years.
- Client project data: returned or deleted within 30 days of the engagement ending, unless the contract says otherwise.
Your rights
Depending on where you live, you have the right to:
- access the personal data we hold about you and get a copy of it;
- correct data that is inaccurate or incomplete;
- have your data deleted;
- restrict or object to how we process it, including for direct marketing;
- receive your data in a portable format;
- withdraw consent at any time, where we rely on consent;
- know what personal information we collect and disclose, and opt out of its sale or sharing (US residents; we do neither);
- nominate someone to exercise your rights if you die or become incapacitated (India);
- not be treated differently for exercising any of these rights.
To use any of these rights, write to contact[at]spanacle.com. We will confirm your identity, then respond within one month (GDPR and UK GDPR), 45 days (CCPA) or 30 days (Australia), whichever is shortest for you. It is free. If you are not happy with our response, you can complain to the authority listed for your region above.
Client data we process for you
When we implement or support an ERP, store or app, we may access personal data inside your systems, such as employee, customer or supplier records. In that role we are your processor. We:
- sign a Data Processing Agreement that meets GDPR Article 28, including transfer safeguards where needed;
- process the data only on your documented instructions and only to deliver the agreed work;
- limit access to the named engineers on your project, all bound by confidentiality;
- prefer anonymised or test data during development, and use production data only when the work needs it;
- help you respond to data subject requests and data protection impact assessments;
- tell you before adding any sub-processor, so you can object.
How we protect data
- Encryption in transit (TLS) for this website, our tools and the systems we deploy.
- Multi-factor authentication and least-privilege access on every account that touches client data.
- Credentials kept in a password manager, never in code or chat.
- A security review in every milestone audit, covering access, dependencies and configuration.
- Backups and access logs on the systems we host.
If a personal data breach affects you or your data, we will tell you without undue delay. Where the law requires, we will notify the relevant authority, which under GDPR and UK GDPR means within 72 hours of becoming aware of it.
Children
Our services are for businesses. We do not knowingly collect personal data from anyone under 18. If you believe we have, contact us and we will delete it.
Changes to this policy
We will update this page when our practices or the law change, and revise the date at the top. If a change is significant, we will tell our clients directly.
Contact
Questions or requests about this policy: contact[at]spanacle.com or +91 99990 09805.