Skip to content

Privacy Policy

Last updated 27 September 2026

This policy explains what personal data Spanacle Software Services ("we", "us") collects when you visit spanacle.com, contact us or work with us, why we collect it, and the rights you have over it. We collect as little as we need, and we never sell it.

Who we are

Spanacle Software Services is a software company based in Delhi, working remotely. For personal data collected through this website and our sales process, Spanacle Software Services is the data controller (the "data fiduciary" under Indian law). For data inside systems we build or support for clients, we act as a data processor on the client's instructions (see "Client data" below).

Privacy and grievance contact: contact[at]spanacle.com.

The laws we follow

We work with clients in the EU, the UK, the US, Australia and India, so we apply the data protection laws of each. Where they differ, we follow the stricter standard.

RegionLawWhere you can complain
European UnionGeneral Data Protection Regulation (EU) 2016/679 (GDPR)Your local data protection authority
United KingdomUK GDPR, the Data Protection Act 2018 and PECRInformation Commissioner's Office (ICO)
United StatesCalifornia Consumer Privacy Act as amended by the CPRA, and other applicable state privacy lawsCalifornia Privacy Protection Agency or your state attorney general
AustraliaPrivacy Act 1988 and the Australian Privacy PrinciplesOffice of the Australian Information Commissioner (OAIC)
IndiaDigital Personal Data Protection Act 2023, and the Information Technology Act 2000 and its rulesData Protection Board of India

What we collect and why

When you send an enquiry

Your name, work email, company, where you are based, your area of interest and your message. We use these only to reply and to prepare a proposal. Our legal basis is taking steps at your request before entering into a contract, and our legitimate interest in responding to business enquiries (GDPR Article 6(1)(b) and (f)).

When you book a call or message us

Your name, email and the details you add when booking through Calendly, or your phone number and messages if you contact us on WhatsApp or by phone. We use them to hold the call and follow up.

When you become a client

Contact details of your team, contracts, invoices and project correspondence. We use them to deliver the work, bill for it and meet our legal obligations (GDPR Article 6(1)(b) and (c)).

When you browse this website

This website does not use advertising or analytics cookies, does not track you across other sites, and serves its fonts from our own domain. Our hosting provider processes standard technical data, such as IP addresses, to deliver and protect the site. If we ever add analytics or marketing cookies, we will ask for your consent first and update this policy.

We do not collect special-category or sensitive personal data through this website, and we do not make automated decisions about you.

Who we share it with

We never sell or rent personal data, and we do not "share" it for cross-context behavioural advertising as defined under the CCPA. We use a small number of service providers that process data on our behalf, under written contracts that require confidentiality and security:

ProviderPurpose
Email delivery serviceDelivers contact-form enquiries to our inbox
CloudflareHosts and secures this website
CalendlySchedules discovery calls you book with us
WhatsApp (Meta)Carries messages if you choose to contact us on WhatsApp
Email and document toolsStore our correspondence and proposals

We may also disclose data where the law requires it, or to protect our legal rights.

International transfers

Our team works from India, so personal data from the EU, the UK and Australia is transferred to and accessed from India. Where the law requires a transfer safeguard, we use the European Commission's Standard Contractual Clauses and, for the UK, the International Data Transfer Addendum. We take reasonable steps to make sure overseas recipients handle data in line with the Australian Privacy Principles. You can ask us for a copy of these safeguards.

How long we keep it

  • Enquiries that do not become projects: deleted 24 months after our last contact.
  • Client contracts and invoices: kept for as long as tax and company law requires, currently up to 8 years.
  • Client project data: returned or deleted within 30 days of the engagement ending, unless the contract says otherwise.

Your rights

Depending on where you live, you have the right to:

  • access the personal data we hold about you and get a copy of it;
  • correct data that is inaccurate or incomplete;
  • have your data deleted;
  • restrict or object to how we process it, including for direct marketing;
  • receive your data in a portable format;
  • withdraw consent at any time, where we rely on consent;
  • know what personal information we collect and disclose, and opt out of its sale or sharing (US residents; we do neither);
  • nominate someone to exercise your rights if you die or become incapacitated (India);
  • not be treated differently for exercising any of these rights.

To use any of these rights, write to contact[at]spanacle.com. We will confirm your identity, then respond within one month (GDPR and UK GDPR), 45 days (CCPA) or 30 days (Australia), whichever is shortest for you. It is free. If you are not happy with our response, you can complain to the authority listed for your region above.

Client data we process for you

When we implement or support an ERP, store or app, we may access personal data inside your systems, such as employee, customer or supplier records. In that role we are your processor. We:

  • sign a Data Processing Agreement that meets GDPR Article 28, including transfer safeguards where needed;
  • process the data only on your documented instructions and only to deliver the agreed work;
  • limit access to the named engineers on your project, all bound by confidentiality;
  • prefer anonymised or test data during development, and use production data only when the work needs it;
  • help you respond to data subject requests and data protection impact assessments;
  • tell you before adding any sub-processor, so you can object.

How we protect data

  • Encryption in transit (TLS) for this website, our tools and the systems we deploy.
  • Multi-factor authentication and least-privilege access on every account that touches client data.
  • Credentials kept in a password manager, never in code or chat.
  • A security review in every milestone audit, covering access, dependencies and configuration.
  • Backups and access logs on the systems we host.

If a personal data breach affects you or your data, we will tell you without undue delay. Where the law requires, we will notify the relevant authority, which under GDPR and UK GDPR means within 72 hours of becoming aware of it.

Children

Our services are for businesses. We do not knowingly collect personal data from anyone under 18. If you believe we have, contact us and we will delete it.

Changes to this policy

We will update this page when our practices or the law change, and revise the date at the top. If a change is significant, we will tell our clients directly.

Contact

Questions or requests about this policy: contact[at]spanacle.com or +91 99990 09805.