Effective Date: 21 July 2026
Spotto Limited ("Spotto", "we", "our", "us") respects your privacy and is committed to protecting your personal information. As a provider of services we may need to obtain certain information about identified or identifiable individuals (Personal Information), including in relation to you and, as applicable, your Users.
This Privacy Policy explains how we collect, use, disclose, and protect Personal Information when you interact with our Website and Service
This Privacy Policy describes our practices. Your use of the Website or Service is not treated as consent to processing. Where we rely on consent as a lawful basis, we obtain it separately and you may withdraw it at any time.
When handling Personal Information we will comply with all privacy laws that we are legally obliged to comply with (Applicable Privacy Laws), including (as applicable), the New Zealand Privacy Act 2020 (NZPA), the Australian Privacy Act 1988, the General Data Protection Regulation (EU) 2016/679 (EU GDPR), the United Kingdom Data Protection Regulation (UK GDPR) and the California Consumer Privacy Act (CCPA/CPRA).
Spotto determines the purposes and means of processing Personal Information collected for its own business activities, including website operation, account administration, billing, support, sales, and marketing. Where Spotto processes Personal Information on behalf of a customer under a data processing agreement, the respective roles and responsibilities are governed by that agreement. Depending on the customer's own role, Spotto may act as a processor or subprocessor.
Unless a term has been defined in this Privacy Policy, it uses the same definitions as those used in our terms of service (available at Terms of Service) (Terms of Service)
We collect Personal Information directly from you, automatically through your use of our Website and/or Services, and in some circumstances from third parties, as follows:
We may obtain business contact information from publicly available sources, professional networks, business partners, and contact-data providers. This may include your name, role, employer, business contact details, and publicly available professional information. We use this information to identify organisations that may benefit from Spotto's services and to contact relevant business representatives. You may ask where we obtained your information, request access or correction, object to further marketing, or request deletion where applicable by emailing our Privacy Officer at [email protected].
Under Applicable Privacy Laws, our lawful bases include:
If you are based in the EU or the UK at the time we are processing your Personal Information, you have the right to object to the way we process your Personal Information where the processing is based on legitimate interests.
We process Personal Information to:
We may also use Personal Information collected for such other purposes that are compatible with the original purpose described above, or that you otherwise consented to from time to time.
We may anonymise and aggregate information such that no person could be re-identified from the information. Aggregated and anonymised data is not Personal Information and this Privacy Policy does not apply to it.
We use the following service providers to operate and support our Website, Service, and business:
| Category | Provider | Customer Data? | Location |
|---|---|---|---|
| Cloud Hosting | Microsoft Azure | Yes | United States, Europe, Australia |
| Website Delivery and Security | Cloudflare | No | Worldwide edge network; logs globally |
| AI Services | Azure AI Foundry | Yes | United States, Europe |
| Authentication | AWS Cognito | Yes | Australia, United States, Europe |
| Payment Processing | Stripe | No | United States |
| Payment Processing | Microsoft Azure | No | Global |
| Analytics | Google Analytics | No | Global |
| CRM, Forms, and Analytics | HubSpot | No | Australia |
| Business Operations | Microsoft 365 | No | Global |
| Meeting Transcription | Granola | No | United States |
Where Personal Information is transferred internationally, we use safeguards required by Applicable Privacy Laws. For disclosures governed by New Zealand law, we use a mechanism permitted by information privacy principle 12, such as contractual safeguards requiring comparable protection. For disclosures governed by Australian law, we take reasonable steps to ensure overseas recipients do not breach the Australian Privacy Principles and remain accountable where required by law. For transfers governed by EU or UK law, we rely on adequacy decisions, approved contractual clauses, or another lawful transfer mechanism.
You can request up-to-date information about our service providers and Customer Data subprocessors by emailing [email protected].
We may disclose your Personal Information:
The rights of disclosure in this section may, if applicable, be subject to further restrictions contained in data processing agreements with our third-party service providers (as applicable).
We do not sell Personal Information or share it for cross-context behavioural advertising. We disclose Personal Information to service providers and other parties only as described in this Section 7 and Section 6.
We may retain all Personal Information that we collect (on both our active systems and our archive systems), for as long as is necessary for us to carry out the purposes for which the information was collected (including for the purpose of providing services to you and resolving any disputes between us) and for as long as required by law (for example, we keep invoice information for 7 years to fulfil our tax obligations). For registration and account information, this means that the information is likely to be retained for the period of time that we consider your Account (or the Account that you are associated with as a User) to be "active".
Personal Information no longer required is securely deleted or anonymized.
We use cookies and similar technologies to:
You can disable non-essential cookies through your browser or system settings.
For more information, see our Cookie Notice at spotto.ai/cookies.
We use safeguards appropriate to the nature of the Personal Information we hold, including:
Despite these measures, no method of transmission over the internet is 100% secure.
If we become aware of a privacy breach affecting Personal Information, we will assess it promptly and notify affected individuals and relevant regulators where required by applicable privacy laws.
We do not use computer programs to make, or substantially and directly assist in making, decisions about individuals that could reasonably be expected to significantly affect their rights or interests.
Our Service may generate automated recommendations about cloud infrastructure configuration, cost, security, performance, and reliability. These recommendations relate to technical resources, not individuals.
You have the right to access your readily retrievable Personal Information that we hold about you, and to ask for it to be corrected if you think it is wrong.
If you are based in the EU or the UK you have the right, under the EU GDPR or the UK GDPR (as applicable), to:
For residents of California and other U.S. states with privacy laws, you have the right to:
To exercise these rights, contact [email protected] with the subject "Privacy Request". We will verify your identity before fulfilling your request. Authorized agents may make requests on your behalf.
We will acknowledge your request promptly and handle it within the timeframe required by Applicable Privacy Laws. For requests governed by New Zealand law, we will notify you of our decision as soon as reasonably practicable and no later than 20 working days after receiving the request, unless the timeframe is lawfully extended. For requests governed by Australian law, we will respond within a reasonable period. Under the EU GDPR and UK GDPR, we will respond within one month, subject to any extension permitted by law.
Please note that in certain circumstances we may refuse to respond to a rights request where we have the right to do so under Applicable Privacy Laws, for example, where a request is manifestly unfounded or excessive
Payments are processed securely through:
We do not store full payment card details.
These providers comply with PCI DSS and their own privacy policies govern their access to and processing of your payment information.
Links to third-party websites or platforms are provided for convenience only. Spotto is not responsible for their privacy practices.
Our Services are accessible worldwide. By using the Website and/or Service, you acknowledge that your information may be processed in countries outside your own, including the United States, New Zealand, the European Union, and Australia, under appropriate data-protection safeguards. Also see section 6 above.
Spotto does not knowingly collect Personal Information from individuals under 16 years of age. If you believe a child has provided us with Personal Information, please contact [email protected] and we will remove it.
If you wish to exercise your rights under this privacy policy or any Applicable Privacy Laws, you can do this by emailing our Privacy Officer at the address set out below. Your email should provide evidence of who you are and set out the details of your request (e.g. the Personal Information, or the correction, that you are requesting).
If you believe we are unlawfully processing your Personal Information and wish to lodge a complaint, you can lodge a complaint with us directly using the above contact details, or you can lodge a complaint: