PRIVACY POLICY

Privacy Policy

This notice covers Spock, spock.chat and seleyalabs.com, operated by Seleya Labs Inc., a Delaware, USA corporation. It explains our purposes, recipients, international processing and your rights. The Terms are the service contract; the DPA governs processing on a customer’s behalf.

Contact support@spock.chat or our privacy contact Louis-Neil Korsten, louis@spock.chat. Seleya’s mailing address is 1111B S Governors Ave STE 56751, Dover, DE 19904, USA. This is a mailing office, not our operating premises. Our personnel work in South Africa.

1. Who determines the processing

Seleya is a controller / responsible party for its own account administration, billing, security, legal compliance and business enquiries. When it handles an organisation’s content to supply instructed services, it acts as a processor / operator under the DPA. A customer may itself be a processor for another organisation.

Roles depend on the purpose. A support message may contain customer content processed on the customer’s behalf as well as contact and case-management information used for our own support administration. An individual using Spock personally is not automatically a GDPR controller merely because they have an account.

If you use an employer’s or another organisation’s Space, that organisation determines its authorised content use, membership and sharing. Its own privacy notice and instructions apply alongside this notice. Contact it about its processing; we will help direct relevant requests.

TTL Technologies (Pty) Ltd is Seleya’s wholly owned South African subsidiary and invoices Enterprise customers. It is a responsible party for its own commercial and statutory records. Personnel engaged through TTL may have authorised access to Spock systems and customer content; where TTL supplies processing services, its operator/subprocessor obligations must cover that access. We do not describe TTL as having no access.

2. Information and sources

InformationTypical sources and examples
Account and authenticationInformation you enter; name, email, password hash, sign-in identifiers and tokens; authorised Apple, Google or Microsoft sign-in. We do not receive your third-party account password through OAuth.
Workspace administrationMemberships, roles, Space settings, sharing, service configuration and connection metadata.
Customer ContentPrompts, conversations, uploads, images, audio, extracted text/tables, connected files and records, generated documents, outputs and their search indexes/embeddings.
Memory and agent contextContext derived from your work, preferences, memory files, summaries and background review results used to personalise or continue work.
Machines and browser sessionsFiles, working directories, execution output, browser profiles, cookies, saved sessions and other state created in hosted work environments.
Usage and securityIP address, device/browser information, request and tool metadata, usage/billing measurements, diagnostic traces, errors and security logs; some traces or submitted reports can contain content.
Billing and contactPlan, invoices, billing contact, company/tax details and payment status. Stripe handles payment credentials; we receive the information needed to administer payments.
Communications and channelsEnquiries, support, feedback and incident correspondence; channel identifiers and messages when Telegram, WhatsApp or other enabled channels are used.
NotificationsDevice/push tokens and notification data if you enable supported notifications, including Firebase Cloud Messaging on supported clients.

Information comes from you, workspace members, connected providers you authorise, documents and websites retrieved for your work, and service/infrastructure telemetry. Providing account and payment details needed for a purchased service is necessary for that service; optional connections are your choice. Do not include information about other people without appropriate authority and a lawful ground.

3. Purposes and lawful grounds

The following grounds apply to our own controller purposes, where GDPR applies. An organisation determines the lawful grounds for processing its content; our DPA processing follows its lawful instructions.

PurposeGDPR ground and relevant limits
Supply an individual’s requested account/service and administer paymentContract necessity, Article 6(1)(b), for that individual’s contract.
Business contacts, organisation account administration and requested supportLegitimate interests, Article 6(1)(f), in delivering and administering the requested business relationship; an individual contractual ground applies where appropriate.
Security, abuse prevention, service reliability and necessary diagnosticsLegitimate interests in protecting people and systems, with necessity, proportionality and the right to object; legal obligations where specifically applicable.
Accounting, tax and legally required records or disclosuresArticle 6(1)(c) where the relevant obligation qualifies; another appropriate lawful ground for obligations outside that scope.
Optional electronic marketingConsent where required, or a legally permitted existing-customer exception with the required opt-out.
Product quality and service developmentNecessary, proportionate operational telemetry and, where used, appropriately aggregated/de-identified information; legitimate interests where identifiable data remains. This does not authorise Customer Content model training.

Under POPIA, the applicable section 11 grounds include contractual necessity, legal obligation, consent where required, and the legitimate interests of the responsible party, data subject or relevant third party, as appropriate to the purpose. Electronic direct marketing must also satisfy section 69; an account is not automatic marketing consent.

Memory/personalisation requires a purpose-specific assessment and applicable lawful ground. It can constitute profiling. Consent or a contract with the uploader does not by itself cover all people mentioned in content, special personal information or every downstream use.

You may withdraw consent without affecting earlier lawful processing, unsubscribe from optional marketing, and object to processing based on legitimate interests. Service and security messages are distinct from marketing.

4. AI, tools, memory and sharing

Spock may automatically route work to our own models or external model APIs, and use separate providers for embeddings, transcription, images or utility tasks. Requests can include relevant conversation context, retrieved passages, files and tool results. Provider use is not limited to a manual model selection.

Our contractual commitment is no training, fine-tuning or development of AI models using Customer Content, by Seleya or its subprocessors. This is separate from storing content to provide your service or provider safety/abuse monitoring. Services and settings must support that commitment; no universal zero-retention or 30-day provider-retention claim is made here.

Memory can be stored in files and updated through background processing. It is used for service context and personalisation, not targeted advertising. Relevant memory can enter later model requests. Do not assume that a dedicated view/edit/delete memory control exists in Settings for every type of memory; contact support for access, correction, objection or deletion requests.

Hosted machines and browser profiles can persist between tasks. Stopping a task or a machine is not necessarily deletion of its files, browser cookies or signed-in session. Disconnecting an integration, signing out of a website and requesting deletion of stored state are different steps.

Agents and scheduled work may retrieve or disclose information through enabled tools and accounts while you are absent. Review instructions, recipients and permissions. Public sharing discloses information to people with the link and can produce copies outside Spock. Workspace administrators and authorised members can see information within their assigned scope.

Spock generates and assists with work; it does not itself decide your legal entitlements. Customers must establish required safeguards for any significant decision involving individuals. AI may make errors; human review remains necessary for consequential uses.

5. Recipients and corporate access

The DPA recipient schedule identifies infrastructure, AI, machine, web, notification, support and channel services, their purposes and location qualifications. The Trust Center explains how to request further details. A provider brand is not proof of the legal entity, account terms, all destinations or retention settings.

Recipients can include:

Our current personnel have production/customer-content access. Access must be limited to authorised purposes, confidentiality and appropriate security; European storage does not eliminate this South African access.

A connected service can act under your own provider contract; it is not automatically our subprocessor. Stripe and channel providers may have independent controller purposes. Legal disclosure requests are assessed for lawfulness, scope and applicable protections.

Google user data

When you connect a Google account, Spock accesses Google user data only to carry out a request you make in Spock:

Nothing is written, changed or sent in your Google account until you approve it in Spock. Google user data is sent to the model/API providers listed above only to produce the result you asked for.

Spock’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we transfer it only to provide or improve the features you use, for security, or to comply with law. We do not use data obtained through Google Workspace APIs to develop, improve or train generalized or non-personalized AI or ML models. No person at Seleya reads your Google user data unless you ask us to (for example, for support), it is needed for security or abuse investigation, or the law requires it.

Google user data stays in Spock only in the chats, files and memory where it was used; deleting them deletes it. OAuth tokens are encrypted at rest. Disconnecting Google in Integrations revokes Spock’s access at Google, and you can also remove it at myaccount.google.com/permissions. This statement is not a claim that a particular OAuth verification or security assessment has been completed.

International processing and safeguards

Seleya is incorporated in the United States; its personnel work in South Africa. European storage, non-European model/API processing, support, channels, onward providers and remote access are separate data flows.

Current observations identify a DigitalOcean Frankfurt database endpoint, an AWS S3 bucket in Frankfurt and Cloudflare R2 buckets with Western Europe placement. R2 placement is not the same as an EU jurisdiction guarantee. These observations do not establish the location of every server, backup, tool or model. A Spock/own-model selection alone is not an EU-only guarantee.

Where GDPR restricts a transfer, the relevant route must have an applicable lawful safeguard, such as a valid adequacy route for the exact recipient/scope, or an applicable Article 46 instrument with completed particulars, required assessment and supplementary measures. The 2021 EU SCCs cannot be assumed to apply to every importer or simply declared signed through this notice. UK and Swiss rules require their own applicable treatment.

For POPIA, a binding agreement providing adequate protection is addressed by section 72(1)(a), including substantially similar conditions and onward-transfer protection. Other section 72 grounds apply only where their actual conditions are met. Processing protected juristic-person information must also be considered.

The DPA sets the obligations for customer processing. We do not represent that every account-specific vendor instrument or transfer assessment has been verified merely because a provider publishes a DPA. You may request information about the safeguards relevant to your processing, and copies where legally available, with necessary redactions for security and others’ confidential information.

7. Retention and deletion

Retention depends on the data’s purpose, the purchased service, your instructions, legal requirements and the copies involved. We must not keep identifiable information longer than the applicable purpose or law justifies.

DataRetention criteria and request handling
Account/workspace and active contentUsed while needed for the account or instructed service; after closure or a valid deletion instruction, the remaining purpose and legal grounds must be assessed and deletion carried out accordingly. An inactive account is not an unlimited retention ground.
Memory, indexes, generated artifacts, machine files and browser profilesCan persist separately from a visible conversation or task. A deletion request must identify and address relevant stored/derived copies, sessions and connected-source re-ingestion.
Diagnostics, security and supportLimited to the period needed for the relevant fault, security, support or dispute purpose; content-bearing records require particular minimisation. There is no verified universal 90–180-day period across all stores.
Provider-managed state and logsDepends on endpoint, files/caches, account settings and applicable legal/safety exceptions; deletion in Spock does not automatically erase every provider copy.
BackupsMust follow a documented lifecycle; deleted content must not be restored to active use. A single verified expiry for all backups has not been established.
Billing, tax and legal recordsKept for the applicable recordkeeping limitation period, with access and use restricted to that purpose. A specific legal hold applies only to the records it requires.

Request access, correction, an export or deletion at support@spock.chat. Some self-service controls are available, but we do not promise that account deletion completes all downstream deletion or cancels every subscription. We will explain applicable exclusions, outstanding copies and completion steps. Where we process for an organisation, we assist its instructions under the DPA. The DPA requires return/deletion when services end; it does not authorise routine 12-month retention of all former customer content.

8. Security and incidents

We use HTTPS/TLS for the service and password hashing. Appropriate measures must address access, infrastructure, software, provider use, backups and incident response; see the DPA security schedule. We do not claim that every connection is TLS 1.3-only, that every storage layer has been independently verified for encryption, or that Spock holds a SOC 2 certification.

Security incident notifications follow the applicable role and law. POPIA operators must escalate immediately where section 21(2) applies; responsible-party notifications under section 22 are made as soon as reasonably possible. Under GDPR, processor customer notice is without undue delay; the controller’s authority deadline is generally 72 hours where Article 33 requires notification.

9. Your rights and complaints

Depending on applicable law, you may request information/access, correction, deletion, restriction, portability, object to relevant processing/profiling, withdraw consent, and complain to a regulator or pursue available legal remedies. POPIA also protects juristic-person information within its scope.

Send requests to support@spock.chat or louis@spock.chat. We may request proportionate identity/authority evidence to avoid disclosing someone else’s information. GDPR requests generally require action within one month, with a permitted extension explained in time. POPIA/PAIA requests follow their applicable requirements and periods. Ordinary privacy rights are not made conditional on paying a PAIA fee or completing a form where law does not require it.

For organisation content, we may refer your request to the responsible customer and assist it. If a request cannot be fulfilled, we must explain the lawful reason and available complaint route.

The South African Information Regulator provides POPIA/PAIA complaint guidance and current contacts. EU/EEA residents may complain to the supervisory authority for their residence, workplace or alleged infringement; UK residents may contact the ICO. These rights do not depend on having complained to us first.

Louis is the privacy contact; this description is not a representation of completed Information Officer registration, an independent GDPR DPO appointment, or an EU/UK representative mandate.

10. Website storage and analytics

Spock uses necessary authentication/session and security storage. The websites are delivered through Cloudflare, which receives request and security information. The Seleya website has used Cloudflare’s performance analytics beacon; it can collect page, device and performance measurements without advertising cookies. Cookie-free does not mean no personal-information processing.

Connected sites opened in a hosted browser can set their own cookies and session state. Their choices and notices are separate from ours. Optional integrations and push notifications create additional processing when enabled. We do not treat Global Privacy Control or Do Not Track as automatically satisfied merely because a page has no advertising cookies; applicable signal duties depend on the actual processing and law.

11. Sensitive information, children and updates

Account holders must be adults. Content about children or special personal information is not authorised merely because an adult uploads it. Establish the applicable lawful grounds, provider permission, risk assessment, safeguards and any necessary prior authorisation before such use. Do not send it to an unapproved workflow.

We will update this notice when relevant processing changes and provide notice of material changes through appropriate service or email channels. A notice update describes processing; it does not create marketing consent, execute a transfer instrument or amend a fixed accepted contract by itself. Previous published texts are preserved.