Privacy Policy

Last updated: 5 August 2026

This version has been rebuilt to reflect the UK Data (Use and Access) Act 2025 (in force from 5 February 2026), the new UK GDPR automated-decision-making regime (Articles 22A–22D), current ICO guidance on AI transparency and fairness, and current data-sharing practices of our key processors and integration partners (Stripe, Xero, Intuit QuickBooks, and Open Banking providers such as TrueLayer and GoCardless). Where our practices go beyond the legal minimum, this is noted. Version 2.0 — supersedes the policy dated 29 June 2026.

1. Who we are

Spask Ltd ("Spaask", "we", "us", or "our") is the developer of Spaask, an AI-powered business operating system for agencies, consultancies, tradespeople, and SMEs. Spaask combines project management, CRM, quoting, finance tracking, HR, booking, and a roster of named AI agents into a single workspace, accessible at https://spaask.com.

Data controller. Spask Ltd is the data controller for account data, billing data, marketing data, and usage/diagnostic data described in this policy, and is registered with the UK Information Commissioner's Office (ICO).

Data processor. Where you or your organisation (the "workspace") upload content — client records, quotes, invoices, project files, HR records, or messages — into Spaask, we act as a data processor on behalf of the workspace administrator, who is the data controller for that content. Our obligations as a processor are set out in our Data Processing Addendum ("DPA"), available on request.

Our registered office is in the United Kingdom and our infrastructure is UK-hosted by default. Questions about this policy or your data rights can be sent to support@spaask.com or to our Data Protection Officer at dpo@spaask.com.

3. Personal data we collect

The data we collect depends on how you and your workspace use Spaask:

  • Account data

    Examples
    Name, email, password hash, MFA/auth tokens, profile photo, role within the workspace
    Source
    You, at sign-up
  • Workspace & business data

    Examples
    Company name, industry, job titles, business address, branding, workspace settings
    Source
    Workspace administrator, during onboarding
  • Client & contact data (workspace content)

    Examples
    Names, emails, phone numbers, addresses of your clients and leads held in Mike (Sales), Eddie (Quotes), and Leo (Client Success)
    Source
    Workspace users, or synced integrations
  • Financial data

    Examples
    Invoices, quotes, payment status, bank connection metadata, transaction categorisation produced by Sarah (Accountant)
    Source
    Workspace users, Stripe, and any Open Banking connection you authorise
  • HR data (where Nova is enabled)

    Examples
    Candidate CVs, interview notes, employee records, right-to-work status
    Source
    Workspace HR administrators, candidates
  • Usage data

    Examples
    Log-ins, feature usage, device/browser type, IP address, timestamps, diagnostic and error events
    Source
    Automatically, from your use of Spaask
  • AI interaction data

    Examples
    Prompts and instructions given to AI agents, agent outputs, and human edits/approvals of those outputs
    Source
    You and your workspace, when using an agent
  • Billing data

    Examples
    Subscription plan, invoices, payment metadata (not full card numbers)
    Source
    Stripe
  • Support & marketing data

    Examples
    Support tickets, feedback, waitlist/demo requests, communication preferences
    Source
    You

4. Why we use personal data, and our legal bases

  • Creating and administering your account and workspace

    Legal basis
    Contract
  • Providing core features (project management, CRM, quoting, invoicing)

    Legal basis
    Contract
  • Powering AI agents you actively invoke (e.g. asking Eddie to draft a quote)

    Legal basis
    Contract, and consent for any optional AI feature
  • Autonomous/background AI actions with material effect (e.g. Nova screening candidates, Leo scoring churn risk)

    Legal basis
    Legitimate interests, with human-in-the-loop safeguards under Articles 22A–22D — see Section 6
  • Securing the platform, preventing fraud and abuse

    Legal basis
    Legitimate interests
  • Aggregated analytics to improve features

    Legal basis
    Legitimate interests
  • Marketing communications, product updates you opt into

    Legal basis
    Consent (withdrawable at any time)
  • Processing subscriptions and payments via Stripe

    Legal basis
    Contract
  • Retrieving bank data via an Open Banking connection

    Legal basis
    Your explicit consent, given directly to the regulated provider
  • Tax, accounting, and regulatory record-keeping

    Legal basis
    Legal obligation

5. How data flows between Spaask's AI agents

Spaask is built around named AI agents, each with a defined role and a single core function. To limit unnecessary data exposure, each agent only accesses the categories of personal data it needs to do its job, and cross-agent handoffs follow the same logic as a real employment hierarchy — for example, Mike (Sales) qualifies a lead, then hands structured deal data to Eddie (Quotes), who hands the accepted quote to Sarah (Accountant) for invoicing. Agents do not have open access to each other's data by default.

  • Max

    Role
    Project Manager
    Data access boundary
    Project, task, and timeline data for the workspace
  • Eddie

    Role
    Quote Manager
    Data access boundary
    Deal data from Mike; pricing and quote records
  • Mike

    Role
    Sales Manager
    Data access boundary
    Lead and contact data; CRM pipeline
  • Sarah

    Role
    Accountant
    Data access boundary
    Accepted quotes, invoices, and connected financial/banking data
  • Ava

    Role
    Receptionist
    Data access boundary
    Incoming enquiries and scheduling data
  • Nova (in development)

    Role
    HR
    Data access boundary
    Candidate and employee records — highest compliance sensitivity; DPIA required before activation
  • Leo (in development)

    Role
    Client Success
    Data access boundary
    Client health and usage signals — DPIA required before activation

Agent Data Access Matrix. Before any new agent is connected to another agent's data, we run it through an internal Agent Data Access Matrix that records the lawful basis, data categories, and retention period for that specific handoff. This is reviewed as part of our DPIA process, particularly for Nova and Leo given their higher-risk processing.

6. AI features, transparency, and automated decision-making

6.1 How we use AI

Spaask's core product is a set of AI agents that draft content, summarise information, categorise transactions, and — for certain enabled features — take autonomous actions within your workspace. AI processing happens using the Anthropic Claude API and, where relevant, models operated by other infrastructure providers under contract.

  • We do not sell your data. We do not use your private workspace content to train public third-party AI models, and our model providers are contractually restricted from doing so with data submitted through Spaask.
  • Human review by default. Agent outputs that affect a client, a candidate, or a financial record (quotes, invoices, HR decisions) are presented to a human user for review or approval before they take effect, unless your workspace administrator has explicitly enabled autonomous mode for a specific workflow.
  • Plain-language explanations. Where an AI agent produces an output that affects you, we aim to explain what data was used and the logic applied in plain language, consistent with ICO guidance on explaining decisions made with AI — not a technical description of the underlying model.

6.2 Automated decision-making (Articles 22A–22D)

Some higher-autonomy features — such as Nova's candidate screening or Leo's churn risk scoring, once activated — may involve solely automated decision-making that has a legal or similarly significant effect on an individual. Under the DUAA's revised UK GDPR regime, this is permitted subject to safeguards, which we implement as follows:

  • Right to human intervention: you or the affected individual can request meaningful human review of any solely automated decision with significant effect.
  • Right to contest: affected individuals may express their point of view and challenge the outcome.
  • Special category data: where a decision would need to rely on special category data (e.g. health information in an HR context), we do not run it on a solely automated basis unless an explicit exception applies, and a DPIA is completed first.
  • Transparency at three points: we tell you about ADM when data is first collected, when you request your data, and at the point ADM is used to make a decision about you.

Nova (HR) and Leo (Client Success) are flagged internally as our highest-risk agents for ADM purposes and will not be activated for autonomous, unreviewed decisions until their DPIAs are complete and reviewed against the ICO's forthcoming statutory Code of Practice on AI and ADM.

6.3 Your controls

  • You can ask which of your data was used to generate a specific AI output.
  • You can request that a human review or override any AI-assisted decision affecting you.
  • Workspace administrators can disable autonomous mode for any agent at the workspace level.

7. Financial data, payments, and Open Banking

7.1 Payments via Stripe

We use Stripe to process subscription payments. We do not store full card numbers on Spaask servers. Stripe acts as an independent controller and/or processor for payment data depending on the activity, and may share data with its own sub-processors, card networks, and identity-verification providers as part of fraud prevention and payment processing. Stripe's international transfers rely on the UK Extension to the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses. You can review Stripe's privacy practices at stripe.com/gb/privacy.

7.2 Accounting integrations (Xero, QuickBooks, and similar)

If you connect Spaask to an external accounting platform such as Xero or Intuit QuickBooks, that platform will share relevant financial data (invoices, contacts, transaction categories) with Spaask, and Spaask will share equivalent data back, strictly to keep records synchronised. Each platform remains a separate data controller for the data it holds, and its own privacy notice governs data on its side of the connection. We only request the scopes needed for the sync you set up, and you can revoke the connection at any time from your workspace settings.

7.3 Open Banking connections

Sarah (Accountant) can optionally connect to your business bank account via a regulated Open Banking provider (an FCA-authorised Account Information Service Provider). We do not build our own bank-scraping technology and we never see or store your online banking credentials — authentication happens directly between you and your bank through the provider's secure API.

  • Consent is yours to give and revoke. Access is granted directly by you to the regulated provider, typically for a maximum 90-day period before reconfirmation is required, and you may revoke access at any time, either in Spaask or directly with your bank.
  • Data minimisation. We request only the data categories needed for bookkeeping and reconciliation (account balance, transaction history, account holder name) — not full online banking access.
  • Regulated intermediaries. Our Open Banking connectivity is provided by FCA-regulated third parties. Their own privacy and consent disclosures are shown to you at the point of connection, in addition to this policy.

8. Third-party integrations and the Spaask app ecosystem

Spaask is designed as a consolidation layer, which means many workspaces connect it to other tools (Google Workspace, calendar providers, e-signature tools, messaging platforms). When you authorise an integration:

  • We only request the minimum data scopes required for that integration to function.
  • Data flows both ways only where you've configured a sync; we do not push workspace data to an integration you haven't connected.
  • Each connected third party is separately responsible, as a controller or processor in its own right, for how it handles data once received — review its own privacy policy before connecting it.
  • You can view and revoke any active integration from workspace settings at any time.

9. When we share personal data

We share personal data only as needed to provide the service, comply with law, or at your direction:

  • UK hosting/infrastructure providers

    Purpose
    Storing and processing Spaask data
    Safeguard
    UK-hosted by default; DPA in place
  • Stripe

    Purpose
    Subscription billing, invoicing, fraud prevention
    Safeguard
    Stripe DPA; UK Extension to the EU-U.S. DPF / SCCs
  • Anthropic (Claude API) and other AI infrastructure providers

    Purpose
    Powering AI agent features
    Safeguard
    Contractual prohibition on using your content to train public models
  • Google (optional)

    Purpose
    Sign-in with Google, calendar sync if enabled
    Safeguard
    OAuth consent; Google's own privacy policy applies
  • Accounting/Open Banking partners you connect

    Purpose
    Financial sync you configure
    Safeguard
    Your direct consent; provider is separately regulated (e.g. FCA)
  • Professional advisers, auditors, regulators, law enforcement

    Purpose
    Legal compliance, protecting rights and safety
    Safeguard
    Only where required or permitted by law
  • Other members of your workspace

    Purpose
    Collaboration, per the roles/permissions your administrator sets
    Safeguard
    Role-based access control within the workspace

We do not sell personal data, and we do not share workspace content with advertising networks or data brokers.

10. International transfers

Spaask is primarily hosted in the United Kingdom. Where a processor we use (for example, a sub-processor of Stripe or an AI infrastructure provider) is located outside the UK or EEA, we require appropriate safeguards before any transfer takes place, such as:

  • UK adequacy regulations, or the equivalent EU adequacy decisions, where available.
  • The UK International Data Transfer Agreement (IDTA), UK Addendum to the EU Standard Contractual Clauses, or EU SCCs.
  • Reliance on the UK Extension to the EU-U.S. Data Privacy Framework, where a US-based processor (such as Stripe) has self-certified.

A current list of our sub-processors and their locations is available on request from dpo@spaask.com.

11. How long we keep data

  • Account data

    Typical retention
    Duration of your account, plus 90 days after closure for recovery, then deleted
  • Workspace content (client records, quotes, invoices, files)

    Typical retention
    Duration of the workspace subscription; exported or deleted at your request on termination, subject to statutory retention below
  • Financial records (invoices, transaction data)

    Typical retention
    6 years, to meet UK tax and accounting obligations
  • HR records (where Nova is active)

    Typical retention
    Set by your workspace's own HR retention schedule, subject to statutory minimums (e.g. right-to-work checks)
  • AI interaction logs (prompts/outputs)

    Typical retention
    12 months, for quality, safety, and dispute-resolution purposes, then anonymised or deleted
  • Usage and diagnostic logs

    Typical retention
    13 months
  • Marketing data

    Typical retention
    Until you withdraw consent or unsubscribe
  • Backups

    Typical retention
    Up to 30 days after deletion from live systems

These are default periods; a workspace administrator can request earlier deletion of workspace content, subject to the legal retention obligations described above (in particular, financial records).

12. Security

We implement technical and organisational measures designed to protect personal data, including encryption in transit and at rest, role-based access control within each workspace, authenticated sessions, per-agent data access boundaries (Section 5), audit logging of AI agent actions, and monitoring for abuse. No online service can guarantee absolute security. You are responsible for safeguarding your credentials and configuring appropriate access within your workspace.

In the event of a personal data breach affecting your data, we will notify the ICO where required within 72 hours of becoming aware, and notify affected workspace administrators without undue delay where the breach is likely to result in a risk to individuals' rights and freedoms.

13. Your rights

Depending on applicable law, you may have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erasure of your data, subject to our legal retention obligations (Section 11).
  • Restrict or object to certain processing, including processing based on legitimate interests.
  • Data portability, for data you provided to us under contract or consent.
  • Withdraw consent at any time, where processing is consent-based, without affecting past lawful processing.
  • Request meaningful human review of, and contest, any solely automated decision with legal or similarly significant effect (Section 6.2).

To exercise these rights, contact support@spaask.com or dpo@spaask.com. We may need to verify your identity before responding, and we will respond within one month, extendable by two further months for complex requests. Manifestly unfounded or excessive requests may be declined or subject to a reasonable fee, as permitted under the DUAA.

If your workspace content is involved, we may need to direct certain requests to your workspace administrator, who is the data controller for that content, and will support them in responding to you.

You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at https://ico.org.uk if you believe our processing violates data protection law.

14. Children

Spaask is a business platform and is not directed at children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will take appropriate steps to delete it.

15. Cookies

We use cookies and similar technologies as described in our Cookies Policy. Essential cookies are required for secure login and core functionality; analytics and any non-essential cookies are set only with your consent, which you can manage at any time via our cookie settings.

16. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in law, our processing activities, or our partners. We will post the updated version on this page and update the "Last updated" date. Where changes are material — for example, a new category of data sharing or a new AI capability with significant effect on individuals — we will use reasonable efforts to notify workspace administrators or registered users directly before the change takes effect.

17. Contact us

For privacy questions, data subject requests, or to review our current sub-processor list and DPA:

  • General privacy queries: support@spaask.com
  • Data Protection Officer: dpo@spaask.com
  • Supervisory authority: Information Commissioner's Office, https://ico.org.uk

Organise your businesswith Spaask

Try all features for 14 days. No credit card required.

Try Free Now