Legal
Last updated September 16, 2026
Spectry is operated by Plexcell Media (Business ID 2493526-5), established in Finland. To provide the Spectry services we engage the third parties listed below. Each is a sub-processor under Article 28 of the GDPR, and we remain responsible to our customers for their performance.
We use three sub-processors. All storage and processing of end-visitor analytics data takes place within the European Union.
We do not use advertising networks, data brokers or audience-enrichment providers, and we do not use any third-party analytics, session replay or heatmap vendor. That functionality is built in-house. We never sell customer or end-visitor data.
We give customers at least 30 days' notice before adding or replacing a sub-processor. During that period you may object on reasonable data-protection grounds, and if we cannot resolve the objection you may terminate the affected part of the services without penalty.
To be notified of changes to this page, email gdpr@spectry.io and we will add you to the notification list.
All Spectry infrastructure runs on Google Cloud. Persistent storage and compute are located in the Netherlands.
| Service | Purpose | Location |
|---|---|---|
| Cloud Run | Application and API hosting | Netherlands |
| Cloud SQL | Accounts, site configuration, opt-in leads, billing state | Netherlands |
| Compute Engine | Analytics event store (self-managed ClickHouse) | EU |
| Cloud Storage | Session replay recordings, screenshots, data export files | EU |
| Cloud CDN | Delivery of the Spectry browser script | Global edge, EU origin |
| Cloud Tasks, Pub/Sub | Asynchronous job and event queues | Netherlands |
| Vertex AI | AI-generated insights and natural-language querying. Inputs are excluded from model training. | EU |
| Google OAuth | Optional "Sign in with Google" | Global |
| reCAPTCHA | Abuse prevention on public forms. Google receives the visitor's IP address for this purpose. | Global |
The Spectry browser script is a static JavaScript file served from a global edge network, so a request for it may be served from outside the EU and the connection metadata for that request, including the visitor's IP address, may be processed at that location.
This concerns only the fetch of a static file. No analytics data, session content or personal data collected by Spectry is transmitted to or stored on the CDN — all analytics data is sent to our API in the EU, and we do not store visitor IP addresses at any point. If you require that static asset delivery also remain within the EU, contact us.
We use Amazon Simple Email Service to send transactional email and scheduled reports. It processes the recipient's name and email address and the content of the message, in Sweden.
Stripe processes subscription billing and payments, handling billing contact details and payment method data. Spectry never receives or stores your card number — it is collected directly by Stripe.
All storage of customer and end-visitor personal data takes place within the EU/EEA. Google, Amazon and Stripe are US-parented, and transfers arising from that relationship are governed by the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. Each provider's data processing addendum is in place.
The only processing that may occur outside the EEA is the global content delivery described above, and the Google sign-in and reCAPTCHA services, which are global by design. None of these involves analytics data collected through Spectry.
Questions about this page, or about how we handle personal data, can be sent to gdpr@spectry.io.