Legal

Privacy notice

Last updated September 16, 2026

Who we are

Spectry is operated by Plexcell Media (Business ID 2493526-5), established in Finland. For questions about this notice or about how we handle personal data, contact gdpr@spectry.io.

Two different roles

This notice covers two distinct situations. Which part applies to you depends on how you encountered Spectry.

If you are…ReadOur role
A Spectry customer, or a visitor to spectry.io Part 1 We are the controller — we decide why and how your data is processed
A visitor to a website that uses Spectry Part 2 We are a processor — the website owner decides, and we act on their instructions

Part 1 — If you are our customer, or you visit spectry.io

What we collect and why

PurposeDataLawful basisRetention
Running your account Name, email address, password (stored hashed) or Google account identifier, organisation and role, account activity Performance of our contractLife of the account, then deleted
Billing and payments Name, billing email and address, subscription and payment status, invoice history. We never receive or store your card number. Contract; legal obligation for accounting records Accounting records kept 6–10 years as required by Finnish law
Service email, alerts and scheduled reports Name, email address, report content Performance of our contract For as long as needed to deliver the service, then deleted
Support and sales enquiries Name, email address, the content of your message and any attachments you send Contract, or our legitimate interest in responding to enquiries Until the matter is resolved and no longer needed for reference
Honouring unsubscribes Email address, date of unsubscribe Legal obligation — we must keep this to keep honouring your objection Kept indefinitely. Deleting it would cause us to email you again.
Measuring use of spectry.io Pseudonymous identifiers, pages viewed, interactions, device and browser, approximate region. No IP address is stored. Your consent, given through our cookie banner Per our data retention periods
Securing our systems Administrator identity, action, timestamp, IP address. This concerns our own staff, not you. Our legitimate interest in detecting misuse of privileged access For as long as needed for security monitoring

Who we share it with

We use three service providers, listed in full with their locations on our sub-processors page: Google Cloud for hosting and storage in the Netherlands, Amazon Web Services for sending email in Sweden, and Stripe for billing.

We also use Google reCAPTCHA on public forms to prevent abuse. Google receives your IP address and interaction signals for this purpose and acts as an independent controller for part of that processing.

We do not sell your data. We do not share it with advertising networks or data brokers. We do not use it to train AI models.

Where your data is held

In the European Union. Some processing — content delivery, Google sign-in and reCAPTCHA — involves global services and may occur outside the EEA. Those transfers are covered by the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

Automated decision-making

We do not make decisions producing legal or similarly significant effects about you by automated means.

Part 2 — If you visited a website that uses Spectry

Website owners embed Spectry to understand how visitors use their site. When you visit such a site, we process data on that site owner's behalf and on their instructions. They decide what is collected and why. They are the controller, and their privacy notice governs.

Only with consent

We collect nothing until the site's consent mechanism indicates you have agreed. Before that, our script neither collects data nor stores any identifier on your device. We also exclude visitors whose browser sends a Do Not Track or Global Privacy Control signal.

What may be collected

Depending on which features the site owner has enabled:

  • A random identifier for your session and your browser, specific to that one website. It has no meaning outside that site and cannot be used to follow you to any other site — including other sites that use Spectry.
  • Pages you view and how you interact with them — navigation, clicks, scrolling, and events the site owner has defined.
  • Technical information — browser, operating system, device type, screen size, referring page, and an approximate geographic region.
  • A recording of your interaction with the page, where the site owner uses session replay. This reconstructs the page and your interaction with it. It is not video or audio, and it does not use your camera or microphone.
  • Survey or feedback responses, if you submit them.
  • Contact details you enter into a form, such as an email address, if the site owner uses our opt-in forms and you choose to submit it.

What is never collected

  • Your IP address is never stored. It is used momentarily to work out an approximate region, then discarded. It is not written to any database, log or backup.
  • What you type into form fields is masked by default before it leaves your browser.
  • Payment card numbers, social security numbers, email addresses and phone numbers appearing in page text are automatically removed before storage.
  • We do not track you across different websites, and we do not build a profile of you that spans more than the single site you are visiting.

One limitation worth knowing

Text that a page displays — as distinct from text you type into a field — is not masked automatically unless the site owner marks it. The automatic removal described above catches payment card numbers, email addresses, phone numbers and social security numbers, but it will not catch something like a name or a postal address shown on an order confirmation page.

Site owners can mark any part of a page to be hidden or excluded from collection entirely, and we tell them to do so where pages display personal information. We mention it here because you should know what a recording can contain.

Your rights

Because the site owner is the controller, requests should go to them — their privacy notice will say how. If you contact us instead, we will point you to the right site owner and let them know you have been in touch.

We have built the tools to service these requests, so a site owner can act on your request across everything we hold: a copy of your data, deletion of it, correction, or restriction.

Your rights in both cases

Under the GDPR you have the right to:

  • Access your personal data and receive a copy
  • Rectify inaccurate or incomplete data
  • Erase your data in certain circumstances
  • Restrict processing in certain circumstances
  • Receive your data in a structured, machine-readable format (portability)
  • Object to processing based on legitimate interests, and to direct marketing at any time
  • Withdraw consent at any time, as easily as you gave it, without affecting processing already carried out

To exercise any of these where we are the controller, contact gdpr@spectry.io. We respond within one month.

Complaints

If you are unhappy with how we have handled your data, you may complain to the Finnish supervisory authority, the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), at tietosuoja.fi. You may also complain to the supervisory authority in your own country of residence.

Cookies and similar technologies

Spectry stores a small identifier in your browser to recognise a session. On spectry.io this is set only after you accept through our banner. On a customer's website it is set only after that site's consent mechanism indicates agreement. Our cookie policy has the detail.

Changes to this notice

We will update this notice when our processing changes, and revise the date at the top. Material changes affecting customers will be notified by email.