Privacy Policy
Last updated: 12 August 2026 · Effective date: 12 August 2026
This Privacy Policy explains how Speredata handles personal data collected through speredata.com and in the course of pre-contractual contact. It is written to meet the transparency requirements of the EU and UK GDPR.
1. Controller and contact
The data controller is Speredata, a company registered. For any privacy matter, including exercising your rights, contact privacy@speredata.com; we will provide our full registered details and, where one is appointed, the contact details of our data protection officer or Article 27 representative on request.
2. What we collect
- Contact and enquiry data — name, business email, company, role and the content of your message when you email us or respond to an enquiry.
- Technical data — IP address, user agent, referring page, requested URL, timestamp and approximate country, recorded in server and security logs.
- Usage data — aggregated page views and device category, only if you consent to analytics cookies.
- Consent records — the cookie choice you made, when you made it and the policy version.
We do not ask for special-category data and ask that you do not send it to us. We do not knowingly collect production data or credentials through this website.
3. Why we use it and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Responding to your enquiry and scoping an engagement | Contact and enquiry data | Steps at your request prior to a contract (Art. 6(1)(b)); legitimate interest in business communication (Art. 6(1)(f)) |
| Operating, securing and troubleshooting the website | Technical data | Legitimate interest in a secure, available service (Art. 6(1)(f)) |
| Understanding how the site is used | Usage data | Consent (Art. 6(1)(a)) |
| Measuring campaign performance | Usage data | Consent (Art. 6(1)(a)) |
| Keeping records of consent and complying with law | Consent records, correspondence | Legal obligation (Art. 6(1)(c)); legitimate interest in defending claims (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have assessed that our interest does not override your rights, and you may object at any time (see section 8).
4. Cookies
Cookies and similar technologies are described in full, including a table of every cookie set, in our Cookie Policy. Non-essential cookies are set only with your consent, which you can change at any time via Cookie settings.
5. Who we share data with
- Infrastructure and security — Cloudflare, Inc. (website delivery, DDoS and bot protection).
- Business tools — our email, document and CRM providers, used to hold correspondence.
- Professional advisers — lawyers, accountants and auditors, where necessary.
- Authorities — where we are legally required to disclose, or to establish or defend legal claims.
Processors act only on our documented instructions under a written data processing agreement. We do not sell personal data.
6. International transfers
Some providers process data outside the EEA or the UK. In those cases we rely on an adequacy decision or on appropriate safeguards — principally the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum — and carry out a transfer risk assessment. A copy of the safeguards is available on request.
7. How long we keep data
- Enquiries that do not lead to an engagement: 24 months from the last contact.
- Client correspondence and contracts: for the engagement plus the statutory limitation period (typically 6–10 years, depending on local law).
- Server and security logs: up to 90 days.
- Analytics data: up to 13 months.
- Consent records: 6 months in the cookie, and up to 3 years in our records as evidence of consent.
8. Your rights
Subject to conditions in applicable law, you have the right to access your data; to rectification; to erasure; to restriction of processing; to data portability; to object to processing based on legitimate interests, including direct marketing; and to withdraw consent at any time without affecting processing carried out before withdrawal. We do not carry out automated decision-making producing legal or similarly significant effects.
To exercise a right, email privacy@speredata.com. We respond within one month and may extend by two further months for complex requests, telling you why. If you are unhappy with our response you may complain to your local supervisory authority — in the UK, the Information Commissioner’s Office.
9. Security
We apply technical and organisational measures appropriate to the risk, including TLS in transit, encryption at rest for business systems, least-privilege access, multi-factor authentication, logging and periodic review. No system is perfectly secure; if a breach is likely to result in a high risk to your rights, we will notify you and the relevant supervisory authority as required by law.
10. Client data we process on instruction
When delivering analytics services we frequently process personal data contained in a client’s systems. In that context the client is the controller and we are a processor, acting only on documented instructions under a data processing agreement that forms part of the engagement contract. If your data was given to us by a company we work for, please direct your request to that company; we will support them in answering it.
11. Children
This website is aimed at business users. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
12. Changes
We update this policy when our practices or the law change. The version on this page is the version in force and the “last updated” date shows when it changed. Material changes will be highlighted on the website.