Privacy policy
In short
- You upload documents and contracts; we store them encrypted, have an artificial-intelligence model read them to extract data and deadlines, and remind you before they expire.
- Every file and every extracted value is encrypted on our servers with a key that exists only for your account. This is not "end-to-end" encryption: the server can decrypt your data when needed to provide the service, and it records every such access in a log you can review.
- Health documents and other "special categories" are read only with your explicit consent, which you can withdraw.
- We do not sell data and do not run profiled advertising. Partner offers appear only if you enabled them, and nothing is sent to the partners.
- You can download everything at any time and delete your account by yourself: after a 14-day grace period we erase everything, key included.
1. Data controller
The data controller is [Company name] S.r.l., registered office [address], VAT no. [VAT number] ("we" or "Spotless"). For any question or to exercise your rights write to info@spotlessapp.it. [If appointed: Data Protection Officer (DPO): name and contact].
2. What data we process
- Account data
- email address, password (stored only as a bcrypt hash), language, time zone, country, notification preferences, plan, registration and last sign-in dates, IP address as a keyed hash (not reversible) for security.
- Documents you upload
- the files (PDF, images) and their original name. They may contain any personal data: yours, your family's, the counterparties of your contracts (see section 9).
- Data extracted from documents
- document category, generated title, counterparty, dates, amounts, periodicity, specific fields, summary, document text and proposed deadlines. They are generated by the AI model and by per-category rules.
- Deadlines, notifications and conversations
- calendar deadlines (including those you add manually), generated notifications, the messages you exchange with the chat and the answers you receive.
- Consents and access log
- each consent with date, version of the accepted document and IP hash; every decryption of your data (who, when, for which operation), which you can review in the "Privacy and data" page.
- Technical data
- application logs containing only numeric identifiers and error codes (never texts or file names), usage counters (storage, documents per month, messages per day), timing and cost of AI model calls.
3. Purposes and legal bases
| Purpose | Legal basis | Notes |
|---|---|---|
| Document archive, extraction of data and deadlines, calendar, in-app and email notifications, chat about your documents | Performance of the contract (art. 6.1.b GDPR) | This is the service itself. Without these operations Spotless cannot work. |
| AI reading of health documents and other special categories (medical reports, certificates, disability, union membership, religion, sexual orientation, proceedings; art. 9 GDPR) | Explicit consent (art. 9.2.a GDPR) | Requested at the first document of this kind. Without consent the document stays in the encrypted archive but is not read by the AI. Revocable at any time from "Privacy and data". |
| Commercial partner offers shown close to a deadline (e.g. an insurance policy about to expire) | Consent (art. 6.1.a GDPR) | Optional, off by default. Matching happens only on our servers: no data is disclosed to partners. Never for special categories. Clicking opens the partner's website, which from then on processes data under its own policy. |
| Aggregate statistics to improve the service (e.g. median amount of a bill per category) | Legitimate interest (art. 6.1.f GDPR) and, for your contribution, optional consent | Only metadata of non-special categories, only values computed over at least 10 users: no figure can be traced to one person. Never document contents. |
| Security, abuse prevention, access log, usage limits | Legitimate interest (art. 6.1.f GDPR) | IP hash, counters, logs without contents. Needed to protect your account and the service. |
| Service emails (address verification, password reset, confirmation codes, deadline digest, deletion confirmation) | Performance of the contract (art. 6.1.b GDPR) | The daily digest can be disabled or set to "discreet" (without naming the document type) in the settings. |
| Compliance with legal obligations and defence of rights | Legal obligation (art. 6.1.c) and legitimate interest (art. 6.1.f) | Only if required by an authority or necessary in a dispute. |
4. How we protect your data: encryption
Every file, every extracted value, every title, label, notification and chat message is encrypted at rest with AES-256-GCM using a key dedicated to your account, itself protected by a master key stored outside the web area of the server. Only the data needed to list, sort and notify stays readable in the database: category, dates, amounts (never for special categories), processing status, counters.
This is not "end-to-end" encryption. It means our servers are able to decrypt your data when needed to provide the service (showing you a document, having the AI read it, sending a reminder) and that, in theory, unauthorised access to the servers could do the same. That is why every decryption is written to the access log you can review, administrative staff have no tools to open documents, titles or chats (they only see metadata and aggregates), and keys are destroyed together with the account.
Identifiers (number plates, customer codes, tax codes) never appear in clear in the database: AI-generated titles are filtered to remove them.
5. Who processes data on our behalf
- Hosting: Beget
- The service, the database and the encrypted files reside on servers of the hosting provider Beget. [To verify and complete before launch: physical location of servers and backups, signature of the DPA under art. 28 GDPR, any transfer outside the EU and safeguards applied (art. 44 ff.)]. The provider performs server backups under its own rules: backups only contain encrypted copies of your files and data.
- Artificial-intelligence provider: Anthropic, through the aiprimetech.io proxy
- To extract data and deadlines and to answer in the chat, the content of your documents (text or page images) and your questions are sent, decrypted and over an encrypted connection, to Anthropic's Claude model through the intermediary service aiprimetech.io. Data is transmitted only for the duration of the processing; under the providers' terms it is not used to train models. The provider may temporarily cache the submitted content (normally a few minutes) to speed up subsequent requests. [To complete: location of the proxy and model servers, DPA and clauses for transfers outside the EU]. You can exclude individual documents from the AI ("archive only"), and documents of special categories are never sent without your explicit consent.
- Service emails are sent by the hosting provider's systems; they contain only the document type and date (never amounts or identifiers) and, in discreet mode, not even the document type.
We do not disclose data to other parties. We use no third-party analytics or advertising services.
6. How long we keep data
- Documents, extracted data, deadlines, chats, notifications: as long as your account exists. A deleted document goes to the trash for 30 days, then it is erased.
- Account: until you delete it. After the deletion request there is a 14-day grace period during which you can cancel; then we erase all your data and your encryption key ("crypto-shredding": any residual copy becomes unreadable).
- Access log and technical logs: up to 24 months, or until account deletion if earlier.
- Hosting provider backups: for the period set by the provider ([to be stated]); they contain only encrypted data and, after account deletion, can no longer be decrypted.
- Queued emails: email text is encrypted and deleted after sending, and in any case within 30 days.
7. Your rights
You have the right to access your data, rectify it, erase it, restrict its processing, object, obtain its portability and withdraw consents at any time (withdrawal does not affect the lawfulness of previous processing). Many rights you exercise yourself from the "Privacy and data" page:
- Access and portability: "Export my data" produces a ZIP archive with your original documents and a JSON file with everything we keep about you.
- Erasure: "Delete my account", with 14 days to change your mind.
- Withdrawal of consents: the optional-consent switches, with the history of every change.
- Rectification: you can correct any extracted value directly in the document page.
For everything else write to info@spotlessapp.it: we reply within 30 days. You also have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it) or with the supervisory authority of your country.
8. Cookies
We only use technical cookies, which require no consent: the session cookie (to recognise you after sign-in, expires on close or after 14 days) and the chosen-language cookie (one year). No profiling, analytics or third-party cookies.
9. Other people's data in your documents
The documents you upload may contain third parties' data (family members, contract counterparties, professionals). We process them exclusively on your behalf and within your personal use of the service; we do not use them for other purposes and do not link them across different users. You decide which documents to upload: informing the people concerned, where required, is your responsibility (art. 14.5.b GDPR).
10. Minors
Spotless is reserved to people aged 14 or over (art. 2-quinquies of the Italian Privacy Code). If we learn that an account belongs to a younger person we close it and erase the data.
11. Transfers outside the European Union
Data resides on the servers of the hosting provider named in section 5. Processing by the AI model may involve the temporary transmission of contents to servers located outside the European Union; in that case the transfer relies on the standard contractual clauses adopted by the European Commission and on the additional safeguards described in section 5. [To confirm based on the signed DPAs].
12. Changes to this policy
If we change something substantial we notify you by email or with a notice at your next sign-in and ask you to review the new version. The version in force is always the one published on this page, with the date shown at the top; recorded consents carry the accepted version.
13. Contacts
[Company name] S.r.l. · [address] · info@spotlessapp.it