Legal
Last updated September 16, 2026
Spectry is operated by Plexcell Media (Business ID 2493526-5), established in Finland. For questions about this notice or about how we handle personal data, contact gdpr@spectry.io.
This notice covers two distinct situations. Which part applies to you depends on how you encountered Spectry.
| If you are… | Read | Our role |
|---|---|---|
| A Spectry customer, or a visitor to spectry.io | Part 1 | We are the controller — we decide why and how your data is processed |
| A visitor to a website that uses Spectry | Part 2 | We are a processor — the website owner decides, and we act on their instructions |
| Purpose | Data | Lawful basis | Retention |
|---|---|---|---|
| Running your account | Name, email address, password (stored hashed) or Google account identifier, organisation and role, account activity | Performance of our contract | Life of the account, then deleted |
| Billing and payments | Name, billing email and address, subscription and payment status, invoice history. We never receive or store your card number. | Contract; legal obligation for accounting records | Accounting records kept 6–10 years as required by Finnish law |
| Service email, alerts and scheduled reports | Name, email address, report content | Performance of our contract | For as long as needed to deliver the service, then deleted |
| Support and sales enquiries | Name, email address, the content of your message and any attachments you send | Contract, or our legitimate interest in responding to enquiries | Until the matter is resolved and no longer needed for reference |
| Honouring unsubscribes | Email address, date of unsubscribe | Legal obligation — we must keep this to keep honouring your objection | Kept indefinitely. Deleting it would cause us to email you again. |
| Measuring use of spectry.io | Pseudonymous identifiers, pages viewed, interactions, device and browser, approximate region. No IP address is stored. | Your consent, given through our cookie banner | Per our data retention periods |
| Securing our systems | Administrator identity, action, timestamp, IP address. This concerns our own staff, not you. | Our legitimate interest in detecting misuse of privileged access | For as long as needed for security monitoring |
We use three service providers, listed in full with their locations on our sub-processors page: Google Cloud for hosting and storage in the Netherlands, Amazon Web Services for sending email in Sweden, and Stripe for billing.
We also use Google reCAPTCHA on public forms to prevent abuse. Google receives your IP address and interaction signals for this purpose and acts as an independent controller for part of that processing.
We do not sell your data. We do not share it with advertising networks or data brokers. We do not use it to train AI models.
In the European Union. Some processing — content delivery, Google sign-in and reCAPTCHA — involves global services and may occur outside the EEA. Those transfers are covered by the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
We do not make decisions producing legal or similarly significant effects about you by automated means.
Website owners embed Spectry to understand how visitors use their site. When you visit such a site, we process data on that site owner's behalf and on their instructions. They decide what is collected and why. They are the controller, and their privacy notice governs.
We collect nothing until the site's consent mechanism indicates you have agreed. Before that, our script neither collects data nor stores any identifier on your device. We also exclude visitors whose browser sends a Do Not Track or Global Privacy Control signal.
Depending on which features the site owner has enabled:
Text that a page displays — as distinct from text you type into a field — is not masked automatically unless the site owner marks it. The automatic removal described above catches payment card numbers, email addresses, phone numbers and social security numbers, but it will not catch something like a name or a postal address shown on an order confirmation page.
Site owners can mark any part of a page to be hidden or excluded from collection entirely, and we tell them to do so where pages display personal information. We mention it here because you should know what a recording can contain.
Because the site owner is the controller, requests should go to them — their privacy notice will say how. If you contact us instead, we will point you to the right site owner and let them know you have been in touch.
We have built the tools to service these requests, so a site owner can act on your request across everything we hold: a copy of your data, deletion of it, correction, or restriction.
Under the GDPR you have the right to:
To exercise any of these where we are the controller, contact gdpr@spectry.io. We respond within one month.
If you are unhappy with how we have handled your data, you may complain to the Finnish supervisory authority, the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), at tietosuoja.fi. You may also complain to the supervisory authority in your own country of residence.
Spectry stores a small identifier in your browser to recognise a session. On spectry.io this is set only after you accept through our banner. On a customer's website it is set only after that site's consent mechanism indicates agreement. Our cookie policy has the detail.
We will update this notice when our processing changes, and revise the date at the top. Material changes affecting customers will be notified by email.