Privacy Policy
Draft version — subject to final legal review
Controller: SpecOne, Inc. [entity details] — E-mail: [privacy@specone.io]. This policy explains how personal data is processed when using the SpecOne platform and website. The Platform is a B2B service; users act for their employer or principal.
1. Data we process
Account data (name, business e-mail, organisation, role, login and MFA metadata); usage and security data (log-ins, actions, technical logs, IP addresses, audit trails); content data (specifications, artwork files and derived scan/translation results, which may incidentally contain personal data); billing data (subscription, plan and credit transactions — payment card data is processed by Stripe only and never stored by SpecOne); website inquiries (name, company, e-mail, message).
2. Purposes
Providing and securing the Platform and performing the contract; billing and statutory retention; service notifications (optional e-mails can be disabled in account settings); responding to inquiries. For EU/UK individuals the legal bases are Art. 6(1)(b), (f) and (c) GDPR.
3. Recipients, processors and international transfers
Processors under data processing agreements: cloud hosting and database [Supabase], file storage [Cloudflare R2], development/deployment platform [Lovable], payment processing [Stripe], e-mail delivery [Resend], and AI model providers for scans and translations [Anthropic, OpenAI, Google]. AI providers process submitted content to return results; API content is not used by these providers to train their models under our agreements.
Transfers of EU/UK personal data to the United States are protected by [the EU-US Data Privacy Framework and/or] Standard Contractual Clauses with the UK Addendum; EU-to-UK transfers rely on the European Commission's adequacy decision for the UK.
4. Retention
Account data for the contract duration; content data until deleted by the customer or on contract end per the DPA; billing records for statutory periods; security logs typically [90] days; website inquiries until handled plus [12] months.
5. EU/EEA individuals (GDPR)
Rights of access, rectification, erasure, restriction, portability and objection (Art. 15–21), and complaint to your local supervisory authority. Requests: [privacy@specone.io].
6. UK individuals (UK GDPR)
The same rights apply; complaints may be made to the Information Commissioner's Office (ICO).
7. California and other US state residents
We process personal information in a B2B context, do not sell personal information and do not share it for cross-context behavioural advertising. California residents have the rights to know, access, correct and delete personal information and to non-discrimination for exercising those rights (CCPA/CPRA). Requests: [privacy@specone.io].
8. Security
Encrypted transport and storage, strict organisation-level access separation (row-level security), signed time-limited file links, multi-factor authentication, role-based access, audit logging, monitoring and alerting, regular security reviews.
