Privacy Policy
Version 2026-10-06
This policy explains what personal data Spendimi collects, why we collect it, who we share it with, and the rights you have over it. It covers both our website and the Spendimi application, including the optional usage-monitoring agent.
1. Who we are
Spendimi provides a SaaS spend and licence management platform. For the account data of our own customers we act as the data controller. For the employee, asset and software-usage data that a customer loads into or generates inside the platform, the customer is the data controller and Spendimi acts as a data processor on their documented instructions.
For any privacy request, write to info@spendimi.com.
2. What data we process
- Account and company data: company name, legal name, tax code, registered address, country, contact name and role, primary and billing email, industry, company size.
- Authentication data: email address, hashed password, email confirmation status, last sign-in date.
- Billing data: billing contact and invoice history. No payment card or bank details are collected or stored in the platform.
- People and asset records: first and last name, work email, employee code, department, job title, office, and the devices or accounts linked to them.
- Contract data: vendors, products, licence names, seats, costs, dates, and any documents you upload.
- Software-usage data (optional agent): the name of the application processes running on a monitored device, the device serial number, computer name, and the local or directory username used to link the device to a person or asset, plus the date and time of last use and last synchronisation.
- Activity log: actions performed inside the platform (creations, edits, assignments, configurations, downloads) with a timestamp.
- Support conversations: messages you send through the in-app chat, with your name, email and company.
The agent does not capture screen contents, keystrokes, browsing history, file contents, webcam or microphone, or the personal use of a device. It records only which applications are in use, and system processes on a published exclusion list are never reported.
3. Why we process it and on what legal basis
| Providing the service | Performance of the contract with the customer (Art. 6.1.b) |
| Billing and accounting | Legal obligation (Art. 6.1.c) |
| Licence usage monitoring | Legitimate interest of the customer in managing company software assets (Art. 6.1.f), on the customer's instructions |
| Security, abuse prevention, audit log | Legitimate interest (Art. 6.1.f) |
| Support and service communications | Performance of the contract (Art. 6.1.b) |
4. A note on monitored employees
If you deploy the Spendimi agent on company devices, you remain responsible for informing your staff before activation, and — where required by national law, including Article 4 of the Italian Workers' Statute — for the prior agreement with employee representatives or authorisation from the labour inspectorate. Spendimi provides an employee information notice you can adapt and distribute; using the agent without it may breach local law.
5. Who we share data with
- Supabase — database, authentication, file storage and serverless functions (hosting in the EU).
- Brevo — transactional and report emails.
- Crisp — in-app support chat.
- Cloudflare — hosting and delivery of the website and application, DNS and network security.
We do not sell personal data and do not use it for advertising. Where a provider processes data outside the European Economic Area, the transfer is covered by the European Commission's Standard Contractual Clauses.
6. How long we keep it
- Account, company and contract data: for the life of the account, then deleted or anonymised on closure.
- Invoices and accounting records: 10 years, as required by tax law, detached from the closed account.
- Software-usage records and unassigned device records: rolling retention set by the customer, by default no longer than 24 months.
- Activity log: 24 months.
- Support conversations: 24 months from the last message.
7. Your rights
You may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest. Customers can export their data and close their account directly from Settings. If you are an employee of one of our customers, address your request to your employer first — as the data controller they can act on it inside the platform; we will support them and will forward any request received directly.
You also have the right to lodge a complaint with your national supervisory authority.
8. Security
Data is encrypted in transit and at rest. Each customer's data is isolated at database level by row-level security rules, so one customer can never read another's records. Agent credentials are stored hashed and can be revoked at any time. Access to production systems is limited to named personnel.
9. Changes
We will publish any update on this page and raise the version number shown above. Material changes are announced by email to account holders before they take effect.