Last Updated: 21 July 2026

    Spotto Privacy Policy

    Effective Date: 21 July 2026

    1. Introduction

    Spotto Limited ("Spotto", "we", "our", "us") respects your privacy and is committed to protecting your personal information. As a provider of services we may need to obtain certain information about identified or identifiable individuals (Personal Information), including in relation to you and, as applicable, your Users.

    This Privacy Policy explains how we collect, use, disclose, and protect Personal Information when you interact with our Website and Service

    This Privacy Policy describes our practices. Your use of the Website or Service is not treated as consent to processing. Where we rely on consent as a lawful basis, we obtain it separately and you may withdraw it at any time.

    When handling Personal Information we will comply with all privacy laws that we are legally obliged to comply with (Applicable Privacy Laws), including (as applicable), the New Zealand Privacy Act 2020 (NZPA), the Australian Privacy Act 1988, the General Data Protection Regulation (EU) 2016/679 (EU GDPR), the United Kingdom Data Protection Regulation (UK GDPR) and the California Consumer Privacy Act (CCPA/CPRA).

    Spotto determines the purposes and means of processing Personal Information collected for its own business activities, including website operation, account administration, billing, support, sales, and marketing. Where Spotto processes Personal Information on behalf of a customer under a data processing agreement, the respective roles and responsibilities are governed by that agreement. Depending on the customer's own role, Spotto may act as a processor or subprocessor.

    Unless a term has been defined in this Privacy Policy, it uses the same definitions as those used in our terms of service (available at Terms of Service) (Terms of Service)

    2. Changes to This Privacy Policy

    • We may update this Privacy Policy from time to time.
    • Any changes will take effect when posted on our Website.
    • If we make material changes, we will notify you by email or through the Service.

    3. Information We Collect

    We collect Personal Information directly from you, automatically through your use of our Website and/or Services, and in some circumstances from third parties, as follows:

    a. Information you provide

    • Name, email address, company name, billing address, and contact details
    • Account registration data and authentication credentials
    • Billing and subscription details (processed by Stripe or Microsoft Azure)
    • Communications with us (e.g., support, feedback, or product requests)

    b. Information collected automatically

    • Usage, telemetry, and analytics data (e.g., IP address, device information, browser type, access times)
    • Cookies and tracking technologies (see Section 9)
    • Cloud resource and performance data you connect via Microsoft Azure or other integrations

    c. Information from third parties

    • Payment processors (Stripe, Microsoft Azure)
    • Business partners, resellers, or distributors
    • Publicly available sources or professional networks (e.g., LinkedIn)

    We may obtain business contact information from publicly available sources, professional networks, business partners, and contact-data providers. This may include your name, role, employer, business contact details, and publicly available professional information. We use this information to identify organisations that may benefit from Spotto's services and to contact relevant business representatives. You may ask where we obtained your information, request access or correction, object to further marketing, or request deletion where applicable by emailing our Privacy Officer at [email protected].

    4. Legal Bases for Processing (GDPR)

    Under Applicable Privacy Laws, our lawful bases include:

    • Performance of a contract (to provide the Website and Service)
    • Legitimate interests (improving our Website and Service, protecting security, and conducting business-to-business sales and marketing)
    • Legal obligation (tax, regulatory compliance)
    • Consent (marketing, cookies, or telemetry tracking where required)

    If you are based in the EU or the UK at the time we are processing your Personal Information, you have the right to object to the way we process your Personal Information where the processing is based on legitimate interests.

    5. How We Use Personal Information

    We process Personal Information to:

    • Provide, operate, and maintain the Website and Service and otherwise carry out our obligations under the Terms of Service
    • Register and manage accounts and authenticate users
    • Process payments and subscriptions via Stripe or Microsoft Azure
    • Communicate about Service updates, support, and security notices
    • Communicate with you (electronically or by telephone) about Spotto products or services that we consider may be of interest to you, and respond to communications received from you. You may opt out of marketing communications at any time using the unsubscribe link in any such communication, or by emailing our Privacy Officer at [email protected]. We will action opt-out requests promptly and will not send further marketing communications once actioned. Opting out of marketing does not affect service, security, or billing communications, which are necessary to provide the Service.
    • responding to any enquiry made by you via email, SMS or any other method, such as to send you requested content, as well as information regarding our products and services
    • to analyze usage of the Website and/or Service, or carry out research and analysis, so we can improve the Website and/or Service
    • carrying out activities connected with the running of our business such as personnel training, quality control, network monitoring, testing and maintenance of computer and other systems, and in connection with the transfer of any part of our business in respect of which you are a customer or a potential customer
    • to protect and/or enforce our legal rights and interests, including defending any claim; and
    • to comply with our legal obligations, including any notification and reporting obligations and any access directions imposed on us by a Government agency or regulatory authority and prevent fraud or misuse.

    We may also use Personal Information collected for such other purposes that are compatible with the original purpose described above, or that you otherwise consented to from time to time.

    We may anonymise and aggregate information such that no person could be re-identified from the information. Aggregated and anonymised data is not Personal Information and this Privacy Policy does not apply to it.

    6. Service Providers and International Transfers

    We use the following service providers to operate and support our Website, Service, and business:

    CategoryProviderCustomer Data?Location
    Cloud HostingMicrosoft AzureYesUnited States, Europe, Australia
    Website Delivery and SecurityCloudflareNoWorldwide edge network; logs globally
    AI ServicesAzure AI FoundryYesUnited States, Europe
    AuthenticationAWS CognitoYesAustralia, United States, Europe
    Payment ProcessingStripeNoUnited States
    Payment ProcessingMicrosoft AzureNoGlobal
    AnalyticsGoogle AnalyticsNoGlobal
    CRM, Forms, and AnalyticsHubSpotNoAustralia
    Business OperationsMicrosoft 365NoGlobal
    Meeting TranscriptionGranolaNoUnited States

    Where Personal Information is transferred internationally, we use safeguards required by Applicable Privacy Laws. For disclosures governed by New Zealand law, we use a mechanism permitted by information privacy principle 12, such as contractual safeguards requiring comparable protection. For disclosures governed by Australian law, we take reasonable steps to ensure overseas recipients do not breach the Australian Privacy Principles and remain accountable where required by law. For transfers governed by EU or UK law, we rely on adequacy decisions, approved contractual clauses, or another lawful transfer mechanism.

    You can request up-to-date information about our service providers and Customer Data subprocessors by emailing [email protected].

    7. Disclosure of Personal Information

    We may disclose your Personal Information:

    • To sub-processors and partners supporting Spotto's operations
    • To authorized resellers or distributors (to fulfil regional sales or support)
    • to respond to due diligence requests and/or transfer personal information in the case of a sale, merger, consolidation, liquidation, reorganization or acquisition of our business;
    • to protect and defend our rights or property and those of our third-party providers (and, where applicable, their end users)
    • to a person who can require us to supply your Personal Information (e.g. a regulatory authority or lay enforcement agency)
    • to any other person or entity authorised by you

    The rights of disclosure in this section may, if applicable, be subject to further restrictions contained in data processing agreements with our third-party service providers (as applicable).

    We do not sell Personal Information or share it for cross-context behavioural advertising. We disclose Personal Information to service providers and other parties only as described in this Section 7 and Section 6.

    8. Data Retention

    We may retain all Personal Information that we collect (on both our active systems and our archive systems), for as long as is necessary for us to carry out the purposes for which the information was collected (including for the purpose of providing services to you and resolving any disputes between us) and for as long as required by law (for example, we keep invoice information for 7 years to fulfil our tax obligations). For registration and account information, this means that the information is likely to be retained for the period of time that we consider your Account (or the Account that you are associated with as a User) to be "active".

    Personal Information no longer required is securely deleted or anonymized.

    9. Cookies and Tracking Technologies

    We use cookies and similar technologies to:

    • Authenticate users and maintain sessions
    • Remember preferences
    • Analyze traffic and usage trends
    • Improve the performance of our website and product

    You can disable non-essential cookies through your browser or system settings.

    For more information, see our Cookie Notice at spotto.ai/cookies.

    10. Protecting Your Information

    We use safeguards appropriate to the nature of the Personal Information we hold, including:

    • Encryption in transit and at rest
    • Access controls and least-privilege principles
    • Monitoring and audit logging where appropriate
    • Managed cloud hosting and security services

    Despite these measures, no method of transmission over the internet is 100% secure.

    11. Data Breach Notification

    If we become aware of a privacy breach affecting Personal Information, we will assess it promptly and notify affected individuals and relevant regulators where required by applicable privacy laws.

    12. Automated Decision Making

    We do not use computer programs to make, or substantially and directly assist in making, decisions about individuals that could reasonably be expected to significantly affect their rights or interests.

    Our Service may generate automated recommendations about cloud infrastructure configuration, cost, security, performance, and reliability. These recommendations relate to technical resources, not individuals.

    13. Data Subject Rights

    You have the right to access your readily retrievable Personal Information that we hold about you, and to ask for it to be corrected if you think it is wrong.

    If you are based in the EU or the UK you have the right, under the EU GDPR or the UK GDPR (as applicable), to:

    • in certain circumstances, have your Personal Information erased;
    • restrict the processing of your Personal Information;
    • move, copy or transfer your Personal Information easily for your own purposes across different services in a safe and secure way;
    • object to processing where we rely on our legitimate interests as the lawful basis for processing;
    • withdraw your consent at any time, where our processing of your Personal Information is based on consent; and
    • lodge a complaint with an appropriate supervisory authority, if you consider that our processing of your Personal Information has breached the EU GDPR or the UK GDPR (as applicable).

    For residents of California and other U.S. states with privacy laws, you have the right to:

    • Know the categories of personal information we collect and their purposes
    • Request access to and deletion of your data
    • Opt out of the sale or sharing of Personal Information. We do not sell Personal Information or share it for cross-context behavioural advertising.
    • Correct inaccurate information
    • Limit use and disclosure of sensitive data

    To exercise these rights, contact [email protected] with the subject "Privacy Request". We will verify your identity before fulfilling your request. Authorized agents may make requests on your behalf.

    We will acknowledge your request promptly and handle it within the timeframe required by Applicable Privacy Laws. For requests governed by New Zealand law, we will notify you of our decision as soon as reasonably practicable and no later than 20 working days after receiving the request, unless the timeframe is lawfully extended. For requests governed by Australian law, we will respond within a reasonable period. Under the EU GDPR and UK GDPR, we will respond within one month, subject to any extension permitted by law.

    Please note that in certain circumstances we may refuse to respond to a rights request where we have the right to do so under Applicable Privacy Laws, for example, where a request is manifestly unfounded or excessive

    14. Payments and Third-Party Platforms

    Payments are processed securely through:

    • Stripe Payments Europe Ltd. (or its affiliates), and
    • Microsoft Azure (via existing Azure bill).

    We do not store full payment card details.

    These providers comply with PCI DSS and their own privacy policies govern their access to and processing of your payment information.

    Links to third-party websites or platforms are provided for convenience only. Spotto is not responsible for their privacy practices.

    15. Cross-Border Users

    Our Services are accessible worldwide. By using the Website and/or Service, you acknowledge that your information may be processed in countries outside your own, including the United States, New Zealand, the European Union, and Australia, under appropriate data-protection safeguards. Also see section 6 above.

    16. Children's Privacy

    Spotto does not knowingly collect Personal Information from individuals under 16 years of age. If you believe a child has provided us with Personal Information, please contact [email protected] and we will remove it.

    17. Contact Details and Complaints

    If you wish to exercise your rights under this privacy policy or any Applicable Privacy Laws, you can do this by emailing our Privacy Officer at the address set out below. Your email should provide evidence of who you are and set out the details of your request (e.g. the Personal Information, or the correction, that you are requesting).

    Privacy Officer

    Spotto Limited

    15 Anzac Road

    Browns Bay, Auckland 0630

    New Zealand

    [email protected]

    If you believe we are unlawfully processing your Personal Information and wish to lodge a complaint, you can lodge a complaint with us directly using the above contact details, or you can lodge a complaint: