1. Scope and responsibility
This notice covers the Spona website, business accounts, enquiries, support and optional financing requests. Top Digital Agency Limited, company number 642562, VAT ID IE3613706OH, 6B Raven Terrace, Galway, H91 H24H, Ireland, provides the ERP. Top Digital d.o.o., MBS 081170998, OIB 72317551155, VAT ID HR72317551155, Vladimira Nazora 23, 49210 Zabok, Croatia, administers financing. For privacy enquiries and rights requests, contact connect@spona.io and identify the service concerned. This address is the privacy contact, not a claim that a statutory Data Protection Officer has been appointed.
2. Two different roles
For managing its business relationships, account security and its own enquiries, the operator acts as a controller. For personal data a customer places in Work, People, Salaries, Purchasing, Sales or Accounting, the customer generally decides the purposes and acts as controller; the operator processes those records on documented instructions under the Data Processing Agreement. A customer acting for another controller must obtain the necessary authority. Financing participants may act as separate controllers for their own assessment and legal obligations; their notices must identify those activities.
3. Data and its sources
Data may include names, work email addresses, company identifiers, account roles, authentication records, enquiries and support messages. Customer-controlled ERP records may include employees, salary amounts, clients, suppliers, project assignments, milestones, orders, invoices and attachments. Financing requests may add identification and contact information, transaction documents, requested amounts and terms, acknowledgements and application status. Sources are you, your organisation and its authorised users, counterparties and documents you supply. Where data comes from another source, the responsible controller must provide the required indirect-collection information, subject to lawful exceptions.
4. Purposes and legal bases
We use necessary account and enquiry information to provide the service, respond to requests and manage the business relationship. Where you personally contract with us, this relies on contract performance or requested pre-contractual steps under Article 6(1)(b) GDPR. For corporate representatives, relationship administration and business communication rely on our legitimate interest in operating and supporting business services under Article 6(1)(f). Security, preventing misuse and establishing or defending legal claims also serve legitimate interests, subject to necessity and your rights. Processing required by a specific legal obligation relies on Article 6(1)(c). Optional tracking and marketing use separate consent where required. Customer-controlled ERP records are processed on documented instructions under the DPA; the customer establishes the basis for those records. Accepting service terms does not consent to every use of data.
5. Employee activity and sensitive records
The ERP code records authenticated activity and visited application routes, and exposes authorised team activity views. Presence buckets and page-view records have a 90-day pruning window, triggered by application activity; this is not a guarantee of deletion at exactly day 90 or a retention rule for all audit logs and backups. Employers must assess necessity, proportionality, access and employee transparency before using these features. Do not use activity alone to make employment decisions. Health, union membership and other special-category data require an Article 9 condition as well as an Article 6 basis; do not upload them unless the service scope and safeguards have been expressly agreed.
6. Recipients and hosting
Authorised personnel and contracted providers may access data where needed to deliver and support the service. Spona hosting is provided by Hetzner in Nuremberg, Germany. Hosting data may include account details, company records, uploaded files and technical logs needed for the service. Relevant transaction data may be shared with the identified financing counterparty and its authorised providers; an enquiry does not grant access to an entire ERP workspace. Professional advisers and competent authorities may receive data where lawfully required. Additional provider, backup and transfer arrangements must be disclosed for the affected service before activation. The German hosting location alone is not a statement that every external service processes data only in Germany. Transfers outside the EEA require applicable safeguards; contact connect@spona.io for information and copies of relevant safeguards.
7. Analytics, datasets and AI
The website includes a consent-gated Google Analytics 4 integration planned for production, currently disconnected pending its measurement ID. See the Cookie notice for controls, data and cookie details. Advertising integrations remain off. The platform includes optional AI briefing code which, when enabled, sends selected findings, narrative labels and figures to the Anthropic API. Reduced or aggregated inputs can still identify a person or reveal confidential business information. Production activation, provider terms, retention and safeguards require confirmation. This notice does not authorise customer personal data or confidential content to train general-purpose models, be sold or be shared across customers. Properly anonymised, non-identifying statistics may support product improvement, research and commercial benchmarks under the safeguards in the Terms and DPA; creating those statistics is itself processing that first needs authority and a lawful basis.
8. Retention and security
We retain account records while needed to administer the service and complete closure; enquiries and support records while needed to respond, resolve the matter and handle related claims; and financing and transaction records for the agreement and applicable legal recordkeeping or claims periods. Customer-controlled ERP records follow documented instructions and the DPA. Legal holds are limited to the relevant records and obligation. Backup copies are restricted to recovery and lawful retention and must not restore deleted records to ordinary use. Contact connect@spona.io for the period or criteria applicable to a specific record and to request deletion. Account access and file access are permission-controlled. No system is absolutely secure; no independent security certification or contractual availability percentage is claimed here. Any specific recovery or availability commitment must be separately agreed.
9. Your choices and rights
Subject to the applicable conditions, you can request access, correction, erasure, restriction and portability, and object to processing based on legitimate interests. You can object to direct marketing at any time and withdraw consent without affecting earlier lawful processing. Contact connect@spona.io and identify the service and request; provide only information reasonably needed to verify identity. Requests are normally answered within one month. A lawful extension of up to two further months requires notice and reasons within the first month. For customer-controlled ERP records, contact your organisation; the operator assists it. You may complain to a supervisory authority in your habitual residence, workplace or the place of the alleged infringement, including the Data Protection Commission in Ireland and AZOP in Croatia. No prior complaint to us is required.
10. Required information and decisions
Without necessary account or transaction information, the relevant service or financing assessment may not be possible. Optional marketing permission must not be a condition of core ERP access. The reviewed financing flow contains a review process; it does not establish that every production decision is manual. Before any solely automated decision with legal or similarly significant effects is used, the responsible controller must establish a lawful basis, provide meaningful information about its logic and consequences, and implement applicable safeguards, including human intervention and challenge rights.