Privacy Policy
Last updated: 5 August 2026
This version has been rebuilt to reflect the UK Data (Use and Access) Act 2025 (in force from 5 February 2026), the new UK GDPR automated-decision-making regime (Articles 22A–22D), current ICO guidance on AI transparency and fairness, and current data-sharing practices of our key processors and integration partners (Stripe, Xero, Intuit QuickBooks, and Open Banking providers such as TrueLayer and GoCardless). Where our practices go beyond the legal minimum, this is noted. Version 2.0 — supersedes the policy dated 29 June 2026.
1. Who we are
Spask Ltd ("Spaask", "we", "us", or "our") is the developer of Spaask, an AI-powered business operating system for agencies, consultancies, tradespeople, and SMEs. Spaask combines project management, CRM, quoting, finance tracking, HR, booking, and a roster of named AI agents into a single workspace, accessible at https://spaask.com.
Data controller. Spask Ltd is the data controller for account data, billing data, marketing data, and usage/diagnostic data described in this policy, and is registered with the UK Information Commissioner's Office (ICO).
Data processor. Where you or your organisation (the "workspace") upload content — client records, quotes, invoices, project files, HR records, or messages — into Spaask, we act as a data processor on behalf of the workspace administrator, who is the data controller for that content. Our obligations as a processor are set out in our Data Processing Addendum ("DPA"), available on request.
Our registered office is in the United Kingdom and our infrastructure is UK-hosted by default. Questions about this policy or your data rights can be sent to support@spaask.com or to our Data Protection Officer at dpo@spaask.com.
2. The legal framework we follow
We process personal data in line with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Data (Use and Access) Act 2025 ("DUAA"), which amended the UK GDPR with effect from 5 February 2026. Where Spaask is used by workspaces or clients in the EEA, we also apply the equivalent EU GDPR standards.
Two DUAA changes are directly relevant to how Spaask works and are reflected throughout this policy:
- Recognised legitimate interests. The DUAA introduced a fixed list of "recognised legitimate interests" (including crime prevention, safeguarding, and certain public-interest activities) that no longer require a full balancing test. We rely on this list only where it genuinely applies and document our reasoning; for everything else we continue to run and record a full legitimate interests assessment.
- Automated decision-making (ADM). Article 22 of the UK GDPR has been replaced by Articles 22A–22D. Solely automated decisions producing legal or similarly significant effects are now permitted with appropriate safeguards, rather than generally prohibited, except where special category data is involved. Section 6 explains how this applies to Spaask's AI agents.
3. Personal data we collect
The data we collect depends on how you and your workspace use Spaask:
Account data
- Examples
- Name, email, password hash, MFA/auth tokens, profile photo, role within the workspace
- Source
- You, at sign-up
Workspace & business data
- Examples
- Company name, industry, job titles, business address, branding, workspace settings
- Source
- Workspace administrator, during onboarding
Client & contact data (workspace content)
- Examples
- Names, emails, phone numbers, addresses of your clients and leads held in Mike (Sales), Eddie (Quotes), and Leo (Client Success)
- Source
- Workspace users, or synced integrations
Financial data
- Examples
- Invoices, quotes, payment status, bank connection metadata, transaction categorisation produced by Sarah (Accountant)
- Source
- Workspace users, Stripe, and any Open Banking connection you authorise
HR data (where Nova is enabled)
- Examples
- Candidate CVs, interview notes, employee records, right-to-work status
- Source
- Workspace HR administrators, candidates
Usage data
- Examples
- Log-ins, feature usage, device/browser type, IP address, timestamps, diagnostic and error events
- Source
- Automatically, from your use of Spaask
AI interaction data
- Examples
- Prompts and instructions given to AI agents, agent outputs, and human edits/approvals of those outputs
- Source
- You and your workspace, when using an agent
Billing data
- Examples
- Subscription plan, invoices, payment metadata (not full card numbers)
- Source
- Stripe
Support & marketing data
- Examples
- Support tickets, feedback, waitlist/demo requests, communication preferences
- Source
- You
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email, password hash, MFA/auth tokens, profile photo, role within the workspace | You, at sign-up |
| Workspace & business data | Company name, industry, job titles, business address, branding, workspace settings | Workspace administrator, during onboarding |
| Client & contact data (workspace content) | Names, emails, phone numbers, addresses of your clients and leads held in Mike (Sales), Eddie (Quotes), and Leo (Client Success) | Workspace users, or synced integrations |
| Financial data | Invoices, quotes, payment status, bank connection metadata, transaction categorisation produced by Sarah (Accountant) | Workspace users, Stripe, and any Open Banking connection you authorise |
| HR data (where Nova is enabled) | Candidate CVs, interview notes, employee records, right-to-work status | Workspace HR administrators, candidates |
| Usage data | Log-ins, feature usage, device/browser type, IP address, timestamps, diagnostic and error events | Automatically, from your use of Spaask |
| AI interaction data | Prompts and instructions given to AI agents, agent outputs, and human edits/approvals of those outputs | You and your workspace, when using an agent |
| Billing data | Subscription plan, invoices, payment metadata (not full card numbers) | Stripe |
| Support & marketing data | Support tickets, feedback, waitlist/demo requests, communication preferences | You |
4. Why we use personal data, and our legal bases
Creating and administering your account and workspace
- Legal basis
- Contract
Providing core features (project management, CRM, quoting, invoicing)
- Legal basis
- Contract
Powering AI agents you actively invoke (e.g. asking Eddie to draft a quote)
- Legal basis
- Contract, and consent for any optional AI feature
Autonomous/background AI actions with material effect (e.g. Nova screening candidates, Leo scoring churn risk)
- Legal basis
- Legitimate interests, with human-in-the-loop safeguards under Articles 22A–22D — see Section 6
Securing the platform, preventing fraud and abuse
- Legal basis
- Legitimate interests
Aggregated analytics to improve features
- Legal basis
- Legitimate interests
Marketing communications, product updates you opt into
- Legal basis
- Consent (withdrawable at any time)
Processing subscriptions and payments via Stripe
- Legal basis
- Contract
Retrieving bank data via an Open Banking connection
- Legal basis
- Your explicit consent, given directly to the regulated provider
Tax, accounting, and regulatory record-keeping
- Legal basis
- Legal obligation
| Purpose | Legal basis |
|---|---|
| Creating and administering your account and workspace | Contract |
| Providing core features (project management, CRM, quoting, invoicing) | Contract |
| Powering AI agents you actively invoke (e.g. asking Eddie to draft a quote) | Contract, and consent for any optional AI feature |
| Autonomous/background AI actions with material effect (e.g. Nova screening candidates, Leo scoring churn risk) | Legitimate interests, with human-in-the-loop safeguards under Articles 22A–22D — see Section 6 |
| Securing the platform, preventing fraud and abuse | Legitimate interests |
| Aggregated analytics to improve features | Legitimate interests |
| Marketing communications, product updates you opt into | Consent (withdrawable at any time) |
| Processing subscriptions and payments via Stripe | Contract |
| Retrieving bank data via an Open Banking connection | Your explicit consent, given directly to the regulated provider |
| Tax, accounting, and regulatory record-keeping | Legal obligation |
5. How data flows between Spaask's AI agents
Spaask is built around named AI agents, each with a defined role and a single core function. To limit unnecessary data exposure, each agent only accesses the categories of personal data it needs to do its job, and cross-agent handoffs follow the same logic as a real employment hierarchy — for example, Mike (Sales) qualifies a lead, then hands structured deal data to Eddie (Quotes), who hands the accepted quote to Sarah (Accountant) for invoicing. Agents do not have open access to each other's data by default.
Max
- Role
- Project Manager
- Data access boundary
- Project, task, and timeline data for the workspace
Eddie
- Role
- Quote Manager
- Data access boundary
- Deal data from Mike; pricing and quote records
Mike
- Role
- Sales Manager
- Data access boundary
- Lead and contact data; CRM pipeline
Sarah
- Role
- Accountant
- Data access boundary
- Accepted quotes, invoices, and connected financial/banking data
Ava
- Role
- Receptionist
- Data access boundary
- Incoming enquiries and scheduling data
Nova (in development)
- Role
- HR
- Data access boundary
- Candidate and employee records — highest compliance sensitivity; DPIA required before activation
Leo (in development)
- Role
- Client Success
- Data access boundary
- Client health and usage signals — DPIA required before activation
| Agent | Role | Data access boundary |
|---|---|---|
| Max | Project Manager | Project, task, and timeline data for the workspace |
| Eddie | Quote Manager | Deal data from Mike; pricing and quote records |
| Mike | Sales Manager | Lead and contact data; CRM pipeline |
| Sarah | Accountant | Accepted quotes, invoices, and connected financial/banking data |
| Ava | Receptionist | Incoming enquiries and scheduling data |
| Nova (in development) | HR | Candidate and employee records — highest compliance sensitivity; DPIA required before activation |
| Leo (in development) | Client Success | Client health and usage signals — DPIA required before activation |
Agent Data Access Matrix. Before any new agent is connected to another agent's data, we run it through an internal Agent Data Access Matrix that records the lawful basis, data categories, and retention period for that specific handoff. This is reviewed as part of our DPIA process, particularly for Nova and Leo given their higher-risk processing.
6. AI features, transparency, and automated decision-making
6.1 How we use AI
Spaask's core product is a set of AI agents that draft content, summarise information, categorise transactions, and — for certain enabled features — take autonomous actions within your workspace. AI processing happens using the Anthropic Claude API and, where relevant, models operated by other infrastructure providers under contract.
- We do not sell your data. We do not use your private workspace content to train public third-party AI models, and our model providers are contractually restricted from doing so with data submitted through Spaask.
- Human review by default. Agent outputs that affect a client, a candidate, or a financial record (quotes, invoices, HR decisions) are presented to a human user for review or approval before they take effect, unless your workspace administrator has explicitly enabled autonomous mode for a specific workflow.
- Plain-language explanations. Where an AI agent produces an output that affects you, we aim to explain what data was used and the logic applied in plain language, consistent with ICO guidance on explaining decisions made with AI — not a technical description of the underlying model.
6.2 Automated decision-making (Articles 22A–22D)
Some higher-autonomy features — such as Nova's candidate screening or Leo's churn risk scoring, once activated — may involve solely automated decision-making that has a legal or similarly significant effect on an individual. Under the DUAA's revised UK GDPR regime, this is permitted subject to safeguards, which we implement as follows:
- Right to human intervention: you or the affected individual can request meaningful human review of any solely automated decision with significant effect.
- Right to contest: affected individuals may express their point of view and challenge the outcome.
- Special category data: where a decision would need to rely on special category data (e.g. health information in an HR context), we do not run it on a solely automated basis unless an explicit exception applies, and a DPIA is completed first.
- Transparency at three points: we tell you about ADM when data is first collected, when you request your data, and at the point ADM is used to make a decision about you.
Nova (HR) and Leo (Client Success) are flagged internally as our highest-risk agents for ADM purposes and will not be activated for autonomous, unreviewed decisions until their DPIAs are complete and reviewed against the ICO's forthcoming statutory Code of Practice on AI and ADM.
6.3 Your controls
- You can ask which of your data was used to generate a specific AI output.
- You can request that a human review or override any AI-assisted decision affecting you.
- Workspace administrators can disable autonomous mode for any agent at the workspace level.
7. Financial data, payments, and Open Banking
7.1 Payments via Stripe
We use Stripe to process subscription payments. We do not store full card numbers on Spaask servers. Stripe acts as an independent controller and/or processor for payment data depending on the activity, and may share data with its own sub-processors, card networks, and identity-verification providers as part of fraud prevention and payment processing. Stripe's international transfers rely on the UK Extension to the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses. You can review Stripe's privacy practices at stripe.com/gb/privacy.
7.2 Accounting integrations (Xero, QuickBooks, and similar)
If you connect Spaask to an external accounting platform such as Xero or Intuit QuickBooks, that platform will share relevant financial data (invoices, contacts, transaction categories) with Spaask, and Spaask will share equivalent data back, strictly to keep records synchronised. Each platform remains a separate data controller for the data it holds, and its own privacy notice governs data on its side of the connection. We only request the scopes needed for the sync you set up, and you can revoke the connection at any time from your workspace settings.
7.3 Open Banking connections
Sarah (Accountant) can optionally connect to your business bank account via a regulated Open Banking provider (an FCA-authorised Account Information Service Provider). We do not build our own bank-scraping technology and we never see or store your online banking credentials — authentication happens directly between you and your bank through the provider's secure API.
- Consent is yours to give and revoke. Access is granted directly by you to the regulated provider, typically for a maximum 90-day period before reconfirmation is required, and you may revoke access at any time, either in Spaask or directly with your bank.
- Data minimisation. We request only the data categories needed for bookkeeping and reconciliation (account balance, transaction history, account holder name) — not full online banking access.
- Regulated intermediaries. Our Open Banking connectivity is provided by FCA-regulated third parties. Their own privacy and consent disclosures are shown to you at the point of connection, in addition to this policy.
8. Third-party integrations and the Spaask app ecosystem
Spaask is designed as a consolidation layer, which means many workspaces connect it to other tools (Google Workspace, calendar providers, e-signature tools, messaging platforms). When you authorise an integration:
- We only request the minimum data scopes required for that integration to function.
- Data flows both ways only where you've configured a sync; we do not push workspace data to an integration you haven't connected.
- Each connected third party is separately responsible, as a controller or processor in its own right, for how it handles data once received — review its own privacy policy before connecting it.
- You can view and revoke any active integration from workspace settings at any time.
10. International transfers
Spaask is primarily hosted in the United Kingdom. Where a processor we use (for example, a sub-processor of Stripe or an AI infrastructure provider) is located outside the UK or EEA, we require appropriate safeguards before any transfer takes place, such as:
- UK adequacy regulations, or the equivalent EU adequacy decisions, where available.
- The UK International Data Transfer Agreement (IDTA), UK Addendum to the EU Standard Contractual Clauses, or EU SCCs.
- Reliance on the UK Extension to the EU-U.S. Data Privacy Framework, where a US-based processor (such as Stripe) has self-certified.
A current list of our sub-processors and their locations is available on request from dpo@spaask.com.
11. How long we keep data
Account data
- Typical retention
- Duration of your account, plus 90 days after closure for recovery, then deleted
Workspace content (client records, quotes, invoices, files)
- Typical retention
- Duration of the workspace subscription; exported or deleted at your request on termination, subject to statutory retention below
Financial records (invoices, transaction data)
- Typical retention
- 6 years, to meet UK tax and accounting obligations
HR records (where Nova is active)
- Typical retention
- Set by your workspace's own HR retention schedule, subject to statutory minimums (e.g. right-to-work checks)
AI interaction logs (prompts/outputs)
- Typical retention
- 12 months, for quality, safety, and dispute-resolution purposes, then anonymised or deleted
Usage and diagnostic logs
- Typical retention
- 13 months
Marketing data
- Typical retention
- Until you withdraw consent or unsubscribe
Backups
- Typical retention
- Up to 30 days after deletion from live systems
| Data category | Typical retention |
|---|---|
| Account data | Duration of your account, plus 90 days after closure for recovery, then deleted |
| Workspace content (client records, quotes, invoices, files) | Duration of the workspace subscription; exported or deleted at your request on termination, subject to statutory retention below |
| Financial records (invoices, transaction data) | 6 years, to meet UK tax and accounting obligations |
| HR records (where Nova is active) | Set by your workspace's own HR retention schedule, subject to statutory minimums (e.g. right-to-work checks) |
| AI interaction logs (prompts/outputs) | 12 months, for quality, safety, and dispute-resolution purposes, then anonymised or deleted |
| Usage and diagnostic logs | 13 months |
| Marketing data | Until you withdraw consent or unsubscribe |
| Backups | Up to 30 days after deletion from live systems |
These are default periods; a workspace administrator can request earlier deletion of workspace content, subject to the legal retention obligations described above (in particular, financial records).
12. Security
We implement technical and organisational measures designed to protect personal data, including encryption in transit and at rest, role-based access control within each workspace, authenticated sessions, per-agent data access boundaries (Section 5), audit logging of AI agent actions, and monitoring for abuse. No online service can guarantee absolute security. You are responsible for safeguarding your credentials and configuring appropriate access within your workspace.
In the event of a personal data breach affecting your data, we will notify the ICO where required within 72 hours of becoming aware, and notify affected workspace administrators without undue delay where the breach is likely to result in a risk to individuals' rights and freedoms.
13. Your rights
Depending on applicable law, you may have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erasure of your data, subject to our legal retention obligations (Section 11).
- Restrict or object to certain processing, including processing based on legitimate interests.
- Data portability, for data you provided to us under contract or consent.
- Withdraw consent at any time, where processing is consent-based, without affecting past lawful processing.
- Request meaningful human review of, and contest, any solely automated decision with legal or similarly significant effect (Section 6.2).
To exercise these rights, contact support@spaask.com or dpo@spaask.com. We may need to verify your identity before responding, and we will respond within one month, extendable by two further months for complex requests. Manifestly unfounded or excessive requests may be declined or subject to a reasonable fee, as permitted under the DUAA.
If your workspace content is involved, we may need to direct certain requests to your workspace administrator, who is the data controller for that content, and will support them in responding to you.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at https://ico.org.uk if you believe our processing violates data protection law.
14. Children
Spaask is a business platform and is not directed at children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will take appropriate steps to delete it.
16. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in law, our processing activities, or our partners. We will post the updated version on this page and update the "Last updated" date. Where changes are material — for example, a new category of data sharing or a new AI capability with significant effect on individuals — we will use reasonable efforts to notify workspace administrators or registered users directly before the change takes effect.
17. Contact us
For privacy questions, data subject requests, or to review our current sub-processor list and DPA:
- General privacy queries: support@spaask.com
- Data Protection Officer: dpo@spaask.com
- Supervisory authority: Information Commissioner's Office, https://ico.org.uk
Organise your businesswith Spaask
Try all features for 14 days. No credit card required.

